
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62631 is an Insufficient Session Expiration vulnerability (CWE-613) in Fortinet FortiOS affecting the SSL VPN component. It allows an attacker to maintain unauthorized access to network resources via an active SSLVPN session that is not properly terminated after a user's password change, under specific conditions outside the attacker's control. Affected versions include FortiOS 6.4 (all versions), 7.0 (all versions), 7.2 (all versions), and 7.4.0; FortiOS 7.6 is not affected. The vulnerability was publicly disclosed on December 9, 2025, with a CVSS v3.1 base score of 5.3–5.6 (Medium) (FortiGuard Advisory).
The root cause is classified as CWE-613 (Insufficient Session Expiration): when a user changes their password, the FortiOS SSLVPN component fails to invalidate existing active sessions under certain conditions. This means a previously authenticated session token remains valid and usable even after the credential change that should have revoked it. The attack vector is network-based, requires no privileges or user interaction, but has high attack complexity due to the dependency on specific conditions outside the attacker's control. No public proof-of-concept or technical write-up detailing the exact triggering conditions has been published (FortiGuard Advisory).
Successful exploitation allows an attacker who has previously obtained valid SSLVPN session credentials to maintain persistent access to protected network resources even after the legitimate user resets their password — a control typically relied upon to revoke unauthorized access. This undermines a key incident response action (password reset) and could allow continued lateral movement, data exfiltration, or persistence within the network. The confidentiality, integrity, and availability impacts are each rated Low, reflecting limited but real unauthorized access potential (FortiGuard Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of disclosure. Fortinet's advisory explicitly states "Known Exploited: No" (FortiGuard Advisory). The EPSS score is approximately 0.041%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The high attack complexity requirement — dependent on specific conditions outside the attacker's control — further limits practical exploitability.
Fortinet has released a fix in FortiOS 7.4.1; users on FortiOS 7.4.0 should upgrade to 7.4.1 or above. Users on FortiOS 6.4 (all versions), 7.0 (all versions), and 7.2 (all versions) must migrate to a fixed release, as no in-branch patch is available for those branches. Fortinet recommends using the official upgrade path tool at https://docs.fortinet.com/upgrade-tool. As interim mitigations, administrators should implement strict session management, regularly review and manually terminate inactive or suspicious VPN sessions, and consider enforcing multi-factor authentication on SSLVPN to reduce the risk of credential-based session hijacking (FortiGuard Advisory).
The vulnerability was reported to Fortinet by Elmaddin Salahov from Caspisec under responsible disclosure, and Fortinet acknowledged the researcher in its advisory (FortiGuard Advisory). The disclosure generated routine tracking activity across vulnerability aggregators (Vulners, VulDB, CVEFeed) and security monitoring platforms (Tenable Nessus plugin 277943), but no significant public researcher commentary or media coverage has been identified, consistent with the Medium severity rating and lack of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."