HIGH

CVE-2025-24472

Fortinet Fortiproxy 2025-02-11 CVSS v3.1
CVSS
8.1
KEV

Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.

Summary dbcve.org

This is an authentication bypass vulnerability in FortiOS and FortiProxy's Security Fabric feature. An unauthenticated remote attacker with prior knowledge of device serial numbers can send crafted CSF (Common Services Framework) proxy requests to gain super-admin privileges on downstream devices when Security Fabric is enabled.

Mitigation

Upgrade to FortiOS 7.0.17/7.0.20+, FortiProxy 7.2.13/7.0.20+ or later versions, or disable Security Fabric if not required while planning the upgrade.

Weakness (CWE)

CWE-288

EPSS Score

7.24%
Probability of exploitation in next 30 days
94.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE