CVE-2025-24472

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Feb 11, 2025
CWE ID 288

Summary

CVE-2025-24472 is a newly disclosed vulnerability affecting FortiOS versions 7.0.0 through 7.0.16 and FortiProxy versions 7.2.0 through 7.2.12, and 7.0.0 through 7.0.19. This issue is classified as an Authentication Bypass Using an Alternate Path or Channel vulnerability (CWE-288). An attacker can exploit this weakness by sending crafted CSF proxy requests, potentially allowing them to gain super-admin privileges remotely. Successful exploitation could result in unauthorized access and control over the affected Fortinet devices. Organizations using these Fortinet versions are urged to apply the available patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share