PT-2025-30014 · Fortinet · Fortisandbox+1

Published

2025-07-08

·

Updated

2025-07-18

·

CVE-2024-27779

CVSS v2.0

8.7

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions FortiSandbox versions prior to 4.4.5 FortiSandbox versions 4.0 through 4.2.6 FortiIsolator versions prior to 2.4 FortiIsolator versions 1.2 through 2.3
Description An insufficient session expiration issue may allow a remote attacker possessing an administrator session cookie to continue using that administrator’s session even after the administrator user has been deleted.
Recommendations FortiSandbox versions prior to 4.4.5: Update to version 4.4.5 or later. FortiSandbox versions 4.0 through 4.2.6: Update to a version later than 4.2.6. FortiIsolator versions prior to 2.4: Update to version 2.4 or later. FortiIsolator versions 1.2 through 2.3: Update to a version later than 2.3.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

BDU:2025-09545
CVE-2024-27779

Affected Products

Fortiisolator
Fortisandbox