Executive brief
An authentication bypass vulnerability in FortiOS and FortiProxy allows a remote unauthenticated attacker to gain super-admin privileges on downstream devices. Exploitation requires the Security Fabric to be enabled and the attacker to have prior knowledge of upstream and downstream device serial numbers to craft malicious CSF proxy requests.
Affected products
- Fortinet FortiOS 7.0.0 through 7.0.16
- Fortinet FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19
Timeline
- 2025-02-11: disclosed: NVD Published Date
- 2025-03-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-03-18: exploited: Reported as exploited in the wild per CISA KEV entry