CVE Vulnerabilities

CVE-2024-27779

Insufficient Session Expiration

Published: Jul 18, 2025 | Modified: Jul 22, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version 4.2.6 and below, 4.0 all versions, 3.2 all versions and FortiIsolator version 2.4 and below, 2.3 all versions, 2.2 all versions, 2.1 all versions, 2.0 all versions, 1.2 all versions may allow a remote attacker in possession of an admin session cookie to keep using that admins session even after the admin user was deleted.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

NameVendorStart VersionEnd Version
FortiisolatorFortinet1.2.0 (including)2.4.5 (excluding)
FortisandboxFortinet3.2.0 (including)4.2.7 (excluding)
FortisandboxFortinet4.4.0 (including)4.4.5 (excluding)

Potential Mitigations

References