Insufficient Session Expiration Vulnerability in FortiSandbox and FortiIsolator by Fortinet
CVE-2024-27779

6.3MEDIUM

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
18 July 2025

What is CVE-2024-27779?

An insufficient session expiration vulnerability exists in FortiSandbox and FortiIsolator that could allow a remote attacker to exploit an admin session cookie. This issue permits unauthorized access to the admin's session, even after the admin user has been deleted. The vulnerability affects various versions of both FortiSandbox and FortiIsolator, potentially compromising security measures and enabling unauthorized activities.

Affected Version(s)

FortiIsolator 2.4.0 <= 2.4.4

FortiIsolator 2.3.0 <= 2.3.4

FortiIsolator 2.2.0

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-27779 : Insufficient Session Expiration Vulnerability in FortiSandbox and FortiIsolator by Fortinet