vulnerability

Fortinet FortiClientEMS: CVE-2021-24019: Session cookie does not expire after logout

Severity
7
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Oct 5, 2021
Added
Nov 20, 2024
Modified
Jul 3, 2025

Description

An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other, hypothetical attacks)

Solution

fortinet-forticlientems-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.