← Back to CVE List
Vulnerability Intelligence Report
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

CVE-2025-24472

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
8.1
HIGH
Exploitability:2.3
Impact Score:5.9
EPSS Probability:3.34%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-288 ↗Execute unauthorized code or commands

Affected Products & Versions

Vendor Product Affected Versions
Fortinet FortiOS 7.0.0 <= 7.0.16 (affected)
Fortinet FortiProxy 7.2.0 <= 7.2.12 (affected), 7.0.0 <= 7.0.19 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
3.342%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityFortinet, Inc. · Vendor · USA
Reserved2025-01-21T20:48:07
Published2025-02-11T16:50:42
Last Updated2026-08-05T03:56:00

LINK COPIED TO CLIPBOARD