A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 may allow an attacker with knowledge of an existing admin account to access the device as a valid admin via an authentication bypass.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-472 |
![]() ![]() |
History
Thu, 29 May 2025 04:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 28 May 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 may allow an attacker with knowledge of an existing admin account to access the device as a valid admin via an authentication bypass. | |
First Time appeared |
Fortinet
Fortinet fortios |
|
Weaknesses | CWE-306 | |
CPEs | cpe:2.3:o:fortinet:fortios:7.4.4:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.4.5:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.4.6:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Fortinet
Fortinet fortios |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: fortinet
Published: 2025-05-28T07:55:49.946Z
Updated: 2025-05-29T03:55:46.210Z
Reserved: 2025-01-02T10:21:04.196Z
Link: CVE-2025-22252

Updated: 2025-05-28T14:11:30.285Z

Status : Awaiting Analysis
Published: 2025-05-28T08:15:21.070
Modified: 2025-05-28T15:01:30.720
Link: CVE-2025-22252

No data.