Executive brief
A security flaw in Fortinet's operating system for firewalls and networking devices could allow unauthorized access to the corporate network. Specifically, a remote user whose digital security certificate has been revoked (cancelled) can still successfully connect to the network using the FortiClient VPN software. This undermines the ability of administrators to immediately block access for former employees or compromised accounts.
Technical details
An Improper Certificate Validation vulnerability (CWE-295) exists in the EAP (Extensible Authentication Protocol) implementation of FortiOS. The root cause is a failure to properly check the revocation status of certificates during the authentication handshake. A remote attacker with a valid but revoked certificate can bypass intended access controls to establish a connection via FortiClient. The vulnerability is reachable over the network and requires the attacker to possess a certificate that was previously trusted. Fortinet has released patches in FortiOS versions 7.6.2 and 7.4.8 to address this issue.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.1, 7.4.0 through 7.4.7
- Fortinet FortiSASE 25.1.a.2
- Siemens RUGGEDCOM APE1808 (Fortigate NGFW) Versions with Fortigate NGFW < V7.4.9 or < V7.6.6
Timeline
- 2025-05-13: advisory: Siemens published initial advisory SSA-864900
- 2025-06-10: disclosed: Initial publication by Fortinet (FG-IR-24-544) and NVD listing