cbcvebase.
CVE-2024-50562
published 2025-06-10

CVE-2024-50562: An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all…

medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EXPLOIT
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out.

Affected

21 ranges
VendorProductVersion rangeFixed in
fortinetfortios
fortinetfortios
fortinetfortios
fortinetfortios>= 6.4.0 < 7.2.117.2.11
fortinetfortios6.4.0 – 6.4.16
fortinetfortios7.0.0 – 7.0.17
fortinetfortios7.2.0 – 7.2.10
fortinetfortios>= 7.4.0 < 7.4.87.4.8
fortinetfortios7.4.0 – 7.4.4
fortinetfortipam
fortinetfortipam
fortinetfortipam1.0.0 – 1.0.3
fortinetfortipam1.1.0 – 1.1.2
fortinetfortipam1.4.0 – 1.4.1
fortinetfortiproxy
fortinetfortiproxy2.0.0 – 2.0.14
fortinetfortiproxy7.0.0 – 7.0.20
fortinetfortiproxy7.2.0 – 7.2.14
fortinetfortiproxy7.4.0 – 7.4.5
fortinetfortisase
fortinetfortisase