CVE-2025-24472 vulnerability in Fortinet Products
Published on February 11, 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote attacker to gain super-admin privileges via crafted CSF proxy requests.
Known Exploited Vulnerability
This Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.
The following remediation steps are recommended / required by April 8, 2025: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Vulnerability Analysis
CVE-2025-24472 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. It has the highest possible exploitability rating (3.9). The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Authentication Bypass Using an Alternate Path or Channel
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
Products Associated with CVE-2025-24472
You can be notified by stack.watch whenever vulnerabilities like CVE-2025-24472 are published in these products:
What versions are vulnerable to CVE-2025-24472?
-
Fortinet FortiProxy Version 7.0.0 Fixed in Version 7.0.20
-
Fortinet FortiProxy Version 7.2.0 Fixed in Version 7.2.13
-
Fortinet FortiOS Version 7.0.0 Fixed in Version 7.0.17