Authentication bypass vulnerability in Fortinet FortiOS and FortiProxy allows remote unauthenticated attackers to gain super-admin privileges via crafted CSF proxy requests when Security Fabric is enabled. This is actively exploited and listed in CISA KEV.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-02-11
Added to CISA KEV: 2025-03-18 35 DAYS BETWEEN CVE AND KEV
CVE-2025-24472 is a critical authentication bypass vulnerability affecting specific versions of Fortinet’s FortiOS and FortiProxy products [1] [5].
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12 ... Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only…
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to gain super- ...
A look at the CVE-2025-24472 and CVE-2024-45591 vulnerabilities in Fortinet, patch status, attack details, and security measures to protect systems.Fortinet recently disclosed CVE-2025-24472, a critical authentication bypass vulnerability in FortiOS and FortiProxy that allows attackers to gain super…
CVE-2025-24472 expands the vulnerability in FortiOS 7.0.0 to 7.0.16 discovered earlier this year and allows remote attackers to gain ... CVE-2025-24472 expands the vulnerability in FortiOS 7.0.0 to 7.0.16 discovered earlier this year and allows remote attackers to gain super-admin privileges.Summary…
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy ... CVE-2025-24472 is a critical authentication bypass vulnerability affecting Fortinet's FortiOS and FortiProxy systems, allowing remote attackers to gain unauth…
This critical authentication bypass flaw impacts FortiOS and FortiProxy systems, enabling remote attackers to exploit specially crafted CSF proxy requests. ... Executive SummaryFebruary 12, 2025 – In today’s advisory update, we present a comprehensive analysis of the recently disclosed vulnerability…