CVE-2024-33507

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/10/2025
Last modified:
15/10/2025

Description

An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker to deauthenticate logged in admins via crafted cookie and remote authenticated read-only attacker to gain write privilege via crafted cookie.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortiisolator:*:*:*:*:*:*:*:* 2.3.0 (including) 2.4.5 (excluding)


References to Advisories, Solutions, and Tools