CVE Vulnerabilities

CVE-2024-27779

Insufficient Session Expiration

Published: Jul 18, 2025 | Modified: Jul 22, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version 4.2.6 and below, 4.0 all versions, 3.2 all versions and FortiIsolator version 2.4 and below, 2.3 all versions, 2.2 all versions, 2.1 all versions, 2.0 all versions, 1.2 all versions may allow a remote attacker in possession of an admin session cookie to keep using that admins session even after the admin user was deleted.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Fortiisolator Fortinet 1.2.0 (including) 2.4.5 (excluding)
Fortisandbox Fortinet 3.2.0 (including) 4.2.7 (excluding)
Fortisandbox Fortinet 4.4.0 (including) 4.4.5 (excluding)

Potential Mitigations

References