Skip to main content

CVE-2024-27782

8.1
HIGHCVSS v3.1 Base Score
0.80%
LOW RiskEPSS (74th percentile)

Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests.

Published: 7/9/2024
Modified: 1/9/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

0.80%LOW Exploitation Risk
74th percentile

This vulnerability has a 0.80% probability of being exploited in the next 30 days, ranking higher than 74% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-613)

CVE-2024-13996CRITICAL 9.8

Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This insufficient session expiration could allow continued unauthorized access to user data and actions even after a password change.

10/30/2025
CVE-2025-54592CRITICAL 9.8

FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during logout. After a user logs out, the session cookie remains active and unchanged. The unchanged cookie could be reused by an attacker if a new session were to be started. This failure to invalidate the session can lead to session hijacking and fixation vulnerabilities. This issue is fixed in version 1.27.0

9/29/2025
CVE-2025-4528MEDIUM 4.3

A weakness has been identified in Dígitro NGC Explorer up to 3.44.15/3.48.21. This affects an unknown function. Executing a manipulation can lead to session expiration. The attack can be launched remotely. Upgrading to version 3.48.22 mitigates this issue. It is recommended to upgrade the affected component. The vendor was contacted early about this disclosure but did not respond in any way.

5/11/2025
CVE-2024-43685CRITICAL 9.8

Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

10/4/2024
CVE-2024-25718CRITICAL 9.8

In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry.

2/11/2024

Similar SeverityHIGH