#VU117144 Insufficient Session Expiration in FortiOS - CVE-2025-25252
Published: October 15, 2025
FortiOS
Fortinet, Inc
Description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to insufficient session expiration in SSLVPN using SAML authentication. A remote attacker (e.g. a former admin whose account was removed and whose session was terminated) in possession of the saml record of a user session can access or re-open that session via re-use of SAML record.