Junglewise Threat Intelligence

CVE-2024-50562: Fortinet FortiOS insufficient session expiration in SSL-VPN

CVE-2024-50562 · Severity: medium · CVSS 4.8 · Published 2025-06-10

Technologies: Siemens Ruggedcom Ape1808, Fortinet FortiOS, Fortinet FortiGate NGFW, Fortinet Fortisase. Vendors: Siemens, Fortinet.

Executive brief

A security flaw has been identified in Fortinet's networking software that manages secure remote access (SSL-VPN). This vulnerability could allow an unauthorized person who has obtained a previous login cookie to reuse it to gain access to the network, even if the original session had already expired or the user had logged out. This could lead to unauthorized access to internal corporate resources and sensitive data.

Technical details

An Insufficient Session Expiration vulnerability (CWE-613) exists in the SSL-VPN component of FortiOS. The flaw allows a session cookie to remain valid or be accepted for re-authentication even after a user has explicitly logged out or the session timeout period has elapsed. An attacker who successfully intercepts or otherwise obtains a valid SSL-VPN session cookie can reuse it to gain unauthorized access to the VPN portal. The attack requires the attacker to already possess a valid cookie (High Attack Complexity) but does not require active user interaction or existing credentials. The issue is resolved in FortiOS versions 7.6.1, 7.4.8, and 7.2.11. Tunnel mode is reportedly not affected.

Affected products

  • Fortinet FortiOS 7.6.0, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10, 7.0 all versions, 6.4 all versions
  • Fortinet FortiSASE 24.4.b
  • Siemens RUGGEDCOM APE1808 (Fortigate NGFW) versions with Fortigate NGFW < V7.4.9

Timeline

  • 2025-05-13: advisory: Siemens published initial advisory SSA-864900
  • 2025-06-10: disclosed: Fortinet published FG-IR-24-339
  • 2025-06-10: advisory: NVD published CVE-2024-50562 detail

References

Related threats