The FortiOS 7.0 to 6.4 all versions and FortiGate 600D series devices have a vulnerability in the SSLVPN that allows an attacker to maintain access to network resources via an active session not terminated after a user's password change under particular conditions outside of the attacker's control. This means potential unauthorized access to sensitive data, if the device is connected to the internet.