Insufficient Session Expiration Vulnerability in Fortinet FortiOS
CVE-2025-62631

5.3MEDIUM

Key Information:

Vendor

Fortinet

Status
Vendor
CVE Published:
9 December 2025

What is CVE-2025-62631?

An insufficient session expiration issue in Fortinet's FortiOS may allow an attacker to maintain unauthorized access to network resources. This vulnerability arises when an active SSLVPN session persists despite a user changing their password, under certain conditions not influenced by the attacker. Users need to be mindful of potential security risks, as this flaw could allow continued access even after credentials have been updated.

Affected Version(s)

FortiOS 7.4.0

FortiOS 7.2.0 <= 7.2.11

FortiOS 7.0.0 <= 7.0.18

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62631 : Insufficient Session Expiration Vulnerability in Fortinet FortiOS