Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-62631


An insufficient session expiration vulnerability [CWE-613] in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to maintain access to network resources via an active SSLVPN session not terminated after a user's password change under particular conditions outside of the attacker's control


Published

2025-12-09T18:16:03.850

Last Modified

2025-12-09T20:29:11.150

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.6 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-613

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System fortinet fortios < 7.4.1 Yes

References