Description
Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to FortiAIOps version 2.0.1 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-24975 | Multiple insufficient session expiration vulnerabilities [CWE-613] in FortiAIOps version 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests. |
References
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-069 |
|
History
Fri, 09 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple insufficient session expiration vulnerabilities [CWE-613] in FortiAIOps version 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests. | Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests. |
Fri, 16 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet fortiaiops |
|
| CPEs | cpe:2.3:a:fortinet:fortiaiops:2.0.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet fortiaiops |
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2026-01-09T16:36:59.722Z
Reserved: 2024-02-26T14:46:31.335Z
Link: CVE-2024-27782
Updated: 2024-08-02T00:41:54.447Z
Status : Modified
Published: 2024-07-09T16:15:05.017
Modified: 2026-01-09T17:15:51.043
Link: CVE-2024-27782
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD