Insufficient Session Expiration in FortiIsolator and FortiSandbox - CVE-2024-27779
Published: July 8, 2025
Vulnerability identifier: #VU112471
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-27779
CWE-ID: CWE-613
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to compromise the affected system.
The vulnerability exists due to insufficient session expiration. A remote attacker in possession of an admin session cookie can keep using that admin's session even after the admin user was deleted.
Affected software
FortiIsolator
FortiSandbox
FortiSandbox
How to mitigate CVE-2024-27779
Install update from vendor's website.
FortiIsolator - update to 2.4.5
FortiSandbox - addressed in versions 4.2.7, 4.4.5
FortiSandbox - addressed in versions 4.2.7, 4.4.5