CVE-2025-24472
Description
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.
Summary dbcve.org
This is an authentication bypass vulnerability in FortiOS and FortiProxy's Security Fabric feature. An unauthenticated remote attacker with prior knowledge of device serial numbers can send crafted CSF (Common Services Framework) proxy requests to gain super-admin privileges on downstream devices when Security Fabric is enabled.
Mitigation
Upgrade to FortiOS 7.0.17/7.0.20+, FortiProxy 7.2.13/7.0.20+ or later versions, or disable Security Fabric if not required while planning the upgrade.