A weak authentication in Fortinet FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to execute unauthorized code or commands via specially crafted http requests
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-010 | Vendor Advisory |
Configurations
History
15 Oct 2025, 17:18
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:fortinet:fortipam:1.5.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiswitchmanager:*:*:*:*:*:*:*:* |
|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-25-010 - Vendor Advisory | |
| First Time |
Fortinet fortipam
Fortinet Fortinet fortiswitchmanager |
14 Oct 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-14 16:15
Updated : 2025-10-15 17:18
NVD link : CVE-2025-49201
Mitre link : CVE-2025-49201
CVE.ORG link : CVE-2025-49201
JSON object : View
Products Affected
fortinet
- fortipam
- fortiswitchmanager
CWE
CWE-1390
Weak Authentication
