CRITICAL

CVE-2025-59718

Fortinet Fortiproxy 2025-12-09 CVSS v3.1
CVSS
9.8
KEV

Description

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

Summary dbcve.org

Improper verification of cryptographic signature in FortiOS, FortiProxy, and FortiSwitchManager allows unauthenticated attackers to bypass FortiCloud SSO login by sending a crafted SAML response message. The vulnerability stems from the system failing to properly validate the digital signature on SAML assertions, enabling authentication bypass.

Mitigation

Apply vendor-supplied patches for all affected versions (FortiOS 7.6.4, 7.4.9, 7.2.12, 7.0.18; FortiProxy 7.6.4, 7.4.11, 7.2.15, 7.0.22; FortiSwitchManager 7.2.7, 7.0.6). This is a critical authentication bypass requiring immediate remediation.

Weakness (CWE)

CWE-347 Improper Signature Verification

EPSS Score

68.29%
Probability of exploitation in next 30 days
99.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE