CVE-2024-33507
published 2025-10-14CVE-2024-33507: An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all…
PriorityP262critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
0.36%
28.6th percentile
An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker to deauthenticate logged in admins via crafted cookie and remote authenticated read-only attacker to gain write privilege via crafted cookie.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiisolator | — | — |
| fortinet | fortiisolator | >= 2.3.0 < 2.4.5 | 2.4.5 |
| fortinet | fortiisolator | 2.3.0 – 2.3.4 | — |
| fortinet | fortiisolator | 2.4.0 – 2.4.4 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for crafted cookie values used to deauthenticate logged-in admins on FortiIsolator (unauthenticated attacker vector) ↗
- →Monitor for crafted cookie values used by authenticated read-only users attempting to gain write privileges on FortiIsolator ↗
- ·Affected versions span FortiIsolator 2.0 all versions, 2.1 all versions, 2.2.0, 2.3 all versions, and 2.4.0 through 2.4.4; ensure patching covers all branches ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in For...
vendor_fortinet·2025-10-14·CVSS 7.4
CVE-2024-33507 [HIGH] CWE-613 An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in For...
FG-IR-24-062: An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in For...
An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker to deauthenticate logged in admins via crafted cookie and remote authenticated read-only attacker to gain write privilege via crafted cookie.
CVEs: CVE-2024-33507
CWEs: CWE-613
CVSS: 7.4 (high)
Affected products: FortiIsolator
GHSA
GHSA-q59r-m5g9-6m54: An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2
ghsa_unreviewed·2025-10-14
CVE-2024-33507 [HIGH] CWE-613 GHSA-q59r-m5g9-6m54: An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2
An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker to deauthenticate logged in admins via crafted cookie and remote authenticated read-only attacker to gain write privilege via crafted cookie.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-10-14
Published