cbcvebase.
CVE-2024-33507
published 2025-10-14

CVE-2024-33507: An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all…

PriorityP262critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
0.36%
28.6th percentile
An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker to deauthenticate logged in admins via crafted cookie and remote authenticated read-only attacker to gain write privilege via crafted cookie.

Affected

4 ranges
VendorProductVersion rangeFixed in
fortinetfortiisolator
fortinetfortiisolator>= 2.3.0 < 2.4.52.4.5
fortinetfortiisolator2.3.0 – 2.3.4
fortinetfortiisolator2.4.0 – 2.4.4

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for crafted cookie values used to deauthenticate logged-in admins on FortiIsolator (unauthenticated attacker vector)
  • Monitor for crafted cookie values used by authenticated read-only users attempting to gain write privileges on FortiIsolator
  • ·Affected versions span FortiIsolator 2.0 all versions, 2.1 all versions, 2.2.0, 2.3 all versions, and 2.4.0 through 2.4.4; ensure patching covers all branches
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.