CVE-2022-45862
An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6
An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions.
FortiProxy 7.2 all versions, 7.0 all versions.
FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions.
FortiSwitchManager 7.2.1 and below, 7.0 all versions GUI may allow attackers to re-use websessions after GUI logout, should they manage to acquire the required credentials.
LOW · CVSS 3.7
EPSS 0.00213
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0