CVE-2024-50562 Details
Description
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out.
A vulnerability allowing insufficient session expiration has been identified in Fortinet FortiOS SSL-VPN. This issue is present in versions 7.6.0, 7.4.6 and below, 7.2.10 and below, all versions of 7.0, and all versions of 6.4. The vulnerability may allow an attacker with a valid cookie from an expired or logged-out session to reauthenticate and gain access to the SSL-VPN portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-864900.html | siemens-SADP | |
| https://fortiguard.fortinet.com/psirt/FG-IR-24-339 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| fortinet fortisase | 24.4.60 |
CPE
Remediation
| |
| fortinet fortios | >= 6.4.0, < 7.2.11 >= 7.4.0, < 7.4.8 7.6.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| Jun 9, 2026 | CVE Modified | siemens-SADP |
| Jul 25, 2025 | Initial Analysis | [email protected] |
| Jun 10, 2025 | New CVE Received | [email protected] |