CRITICAL

CVE-2025-49201

Fortinet Fortipam 2025-10-14 CVSS v3.1
CVSS
9.8

Description

A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to execute unauthorized code or commands via specially crafted http requests

Summary dbcve.org

A weak authentication vulnerability in Fortinet FortiPAM and FortiSwitchManager allows unauthenticated attackers to execute arbitrary code or commands by sending specially crafted HTTP requests. The vulnerability stems from insufficient authentication controls that can be bypassed or exploited through malformed requests.

Mitigation

Apply vendor-supplied patches or upgrade to FortiPAM 1.5.1 or later and FortiSwitchManager 7.2.5 or later. Restrict administrative interface access to trusted networks until patches are applied.

Weakness (CWE)

CWE-1390

EPSS Score

0.58%
Probability of exploitation in next 30 days
46.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE