---
id: CVE-2025-25252
title: >-
  An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN
  7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through
  7.0.16, 6.4 all versions may allow a remote attacker (e.g
summary: >-
  An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN
  7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through
  7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin
  whose a…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C'
cvssSource: cna
cwe:
  - CWE-613
vendor: Fortinet
product: FortiOS
affected:
  - FortiOS >= 7.6.0 <= 7.6.2
  - FortiOS >= 7.4.0 <= 7.4.6
  - FortiOS >= 7.2.0 <= 7.2.10
  - FortiOS >= 7.0.0 <= 7.0.16
  - FortiOS >= 6.4.0 <= 6.4.16
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-12T00:00:00+00:00'
published: '2025-10-14'
updated: '2026-09-13'
sourceUpdated: '2026-09-13T03:55:21.219Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2025-25252'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-24-487'
    label: 'https://fortiguard.fortinet.com/psirt/FG-IR-24-487'
tags:
  - cve.org
epss: 0.00337
epssPercentile: 0.24283
ingestedAt: '2026-09-14T15:23:07.477Z'
---

## Overview

An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and whose session was terminated) in possession of the SAML record of a user session to access or re-open that session via re-use of SAML record.

## Affected

- `FortiOS >= 7.6.0 <= 7.6.2`
- `FortiOS >= 7.4.0 <= 7.4.6`
- `FortiOS >= 7.2.0 <= 7.2.10`
- `FortiOS >= 7.0.0 <= 7.0.16`
- `FortiOS >= 6.4.0 <= 6.4.16`

## Remediation

Upgrade to FortiOS version 7.6.3 or above
Upgrade to FortiOS version 7.4.7 or above
