CVE-2025-24472

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote attacker to gain super-admin privileges via crafted CSF proxy requests.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

History

19 Mar 2025, 20:21

Type Values Removed Values Added
First Time Fortinet fortios
Fortinet
Fortinet fortiproxy
CPE cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
CWE CWE-306
References () https://fortiguard.fortinet.com/psirt/FG-IR-24-535 - () https://fortiguard.fortinet.com/psirt/FG-IR-24-535 - Vendor Advisory

19 Mar 2025, 01:00

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de omisión de autenticación mediante una ruta o canal alternativo [CWE-288] que afecta a FortiOS 7.0.0 a 7.0.16 y FortiProxy 7.2.0 a 7.2.12, 7.0.0 a 7.0.19 puede permitir que un atacante remoto obtenga privilegios de superadministrador a través de solicitudes de proxy CSF manipuladas.

11 Feb 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 17:15

Updated : 2025-03-19 20:21


NVD link : CVE-2025-24472

Mitre link : CVE-2025-24472

CVE.ORG link : CVE-2025-24472


JSON object : View

Products Affected

fortinet

  • fortiproxy
  • fortios
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel

CWE-306

Missing Authentication for Critical Function