SB2025120945 - Insufficient Session Expiration in FortiOS
Published: December 9, 2025
Security Bulletin ID
SB2025120945
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insufficient Session Expiration (CVE-ID: CVE-2025-62631)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to insufficient session expiration in SSLVPN. An attacker can maintain access to network resources via an active session not terminated after a user's password change under particular conditions outside of the attacker's control.
Remediation
Install update from vendor's website.