A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN may allow an attacker to retrieve a logged-in SSL VPN user’s credentials should that attacker be able to read the session file stored on the targeted device’s system.