Fortinet FortiOS Insufficient Session Expiration
Fortinet's FortiOS SSL VPN, which lets remote employees log into a company network, has a bug where a leftover login record tied to SAML single sign-on can let someone reuse an old session. This can work even after the original account was deleted and its session was supposedly ended.
- Severity
- MediumCVSS 3.1 · 4.8 · fortinet.com
- Fix
- Fixed in 7.6.3
- Affected versions
- 7.6.0 through 7.6.2; 7.4.0 through 7.4.6; 7.2.0 through 7.2.10+2 more
- Weakness
- CWE-613
- Exploit likelihood
- 0.28% in 30 daysEPSS, higher than 20% of known flaws
- Affects
- FortiOS
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: no · Technical impact: partial
- EU ID
- EUVD-2025-34237ENISA vulnerability database
How it works
- FortiOS SSL VPN can authenticate users through SAML single sign-on, and FortiOS keeps a stored SAML record tied to that login session.
- The flaw is that this record is not reliably invalidated once the session or the underlying account is supposed to be gone.
- Someone who is in possession of that old SAML record, for example a former admin whose account was already removed and whose session was terminated, can reuse the record to access or re-open the original session.
- No password is required, just possession of the leftover record.
- The public advisory does not explain how an attacker would first obtain that record.
What to do
If you run FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, or any 6.4.x build, and your SSL VPN uses SAML single sign-on, compare your version against Fortinet's advisory FG-IR-24-487. Confirm whether SAML SSO is enabled for SSL VPN logins on your device, since the issue only applies to that login path.
Update FortiOS to 7.6.3 or later if you run the 7.6 branch, or to 7.4.7 or later if you run 7.4, following Fortinet's advisory FG-IR-24-487. Consult that same advisory for the 7.2, 7.0, and 6.4 branches, since the retrieved evidence does not list specific fixed builds for those branches beyond the general update guidance.
Technical details
CVE-2025-25252 is an insufficient session expiration flaw (CWE-613) in FortiOS SSL VPN's SAML authentication handling. A stored SAML session record is not reliably invalidated, so a party in possession of that record can reuse it to access or re-open the associated SSL VPN session, including after the underlying account was removed. CVSS 3.1 scoring varies between sources (4.3 to 6.5, AC:H or AC:L, PR:N, UI:N, C:L/I:L/A:N), reflecting differing views on attack complexity, but all agree impact is limited to confidentiality and integrity with no availability impact. Fortinet's PSIRT tracks it as FG-IR-24-487.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity High Attack depends on conditions outside the attacker's control
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact Low Some data can be read
- Integrity impact Low Some data can be modified
- Availability impact None No availability impact
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N Open in FIRST.org calculatorReferences
- tenable.com · CVE-2025-25252 third party advisory vdb entry
- cve.org · CVERecord vdb entry
- cvefeed.io · CVE-2025-25252 third party advisory vdb entry
- euvd.enisa.europa.eu · EUVD-2025-34237 vdb entry
- cveawg.mitre.org · CVE-2025-25252
- fortiguard.fortinet.com · FG-IR-24-487