Home

Description

An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker to deauthenticate logged in admins via crafted cookie and remote authenticated read-only attacker to gain write privilege via crafted cookie.

PUBLISHED Reserved 2024-04-23 | Published 2025-10-14 | Updated 2025-10-14 | Assigner fortinet




HIGH: 7.0CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H/E:P/RL:X/RC:X

Problem types

Denial of service, Privilege escalation

Product status

Default status
unaffected

2.4.0
affected

2.3.0
affected

References

fortiguard.fortinet.com/psirt/FG-IR-24-062

cve.org (CVE-2024-33507)

nvd.nist.gov (CVE-2024-33507)

Download JSON