{"api_version":"1","generated_at":"2026-07-25T00:47:41+00:00","cve":"CVE-2020-6649","urls":{"html":"https://cve.report/CVE-2020-6649","api":"https://cve.report/api/cve/CVE-2020-6649.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-6649","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-6649"},"summary":{"title":"CVE-2020-6649","description":"An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other, hypothetical attacks)","state":"PUBLIC","assigner":"psirt@fortinet.com","published_at":"2021-02-08 16:15:00","updated_at":"2021-02-10 19:02:00"},"problem_types":["CWE-613"],"metrics":[],"references":[{"url":"https://fortiguard.com/advisory/FG-IR-20-011","name":"https://fortiguard.com/advisory/FG-IR-20-011","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Session ID does not expire after logout in FortiIsolator | FortiGuard","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-6649","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-6649","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"6649","vulnerable":"1","versionEndIncluding":"2.0.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fortinet","cpe5":"fortiisolator","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-6649","ASSIGNER":"psirt@fortinet.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Fortinet","product":{"product_data":[{"product_name":"Fortinet FortiIsolator","version":{"version_data":[{"version_value":"FortiIsolator 2.0.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Escalation of privilege"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://fortiguard.com/advisory/FG-IR-20-011","url":"https://fortiguard.com/advisory/FG-IR-20-011"}]},"description":{"description_data":[{"lang":"eng","value":"An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other, hypothetical attacks)"}]}},"nvd":{"publishedDate":"2021-02-08 16:15:00","lastModifiedDate":"2021-02-10 19:02:00","problem_types":["CWE-613"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fortinet:fortiisolator:*:*:*:*:*:*:*:*","versionEndIncluding":"2.0.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"6649","Ordinal":"166912","Title":"CVE-2020-6649","CVE":"CVE-2020-6649","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"6649","Ordinal":"1","NoteData":"An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other, hypothetical attacks)","Type":"Description","Title":null},{"CveYear":"2020","CveId":"6649","Ordinal":"2","NoteData":"2021-02-08","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"6649","Ordinal":"3","NoteData":"2021-02-08","Type":"Other","Title":"Modified"}]}}}