CVE-2024-50562: Insufficient Session Expiration in SSL-VPN cookie
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out.
Other sources
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOS SSL-VPNto a version that resolves this vulnerability.Fixed in 7.2.11 - Upgrade
Upgrade
FortiOS SSL-VPNto a version that resolves this vulnerability.Fixed in 7.4.8 - Upgrade
Upgrade
FortiOS SSL-VPNto a version that resolves this vulnerability.Fixed in 7.6.1 - Upgrade
Upgrade
FortiSASEto a version that resolves this vulnerability.Fixed in 24.4.c
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50562?
CVE-2024-50562 is categorized as a critical vulnerability due to its potential for unauthorized access.
How do I fix CVE-2024-50562?
To mitigate CVE-2024-50562, upgrade FortiOS to versions 7.6.1 or later, 7.4.8 or later, or 7.2.11 or later depending on your current version.
What types of systems are affected by CVE-2024-50562?
CVE-2024-50562 affects various versions of FortiOS and the FortiSASE product.
What does CVE-2024-50562 vulnerability allow an attacker to do?
CVE-2024-50562 allows an attacker to reuse session cookies to log into the SSL-VPN portal even after the session has expired.
When was CVE-2024-50562 published?
CVE-2024-50562 was published recently and users are advised to apply the recommended updates swiftly.