Junglewise Threat Intelligence

CVE-2025-24472: Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

CVE-2025-24472 · Severity: critical · CVSS 8.1 · Exploited in the wild · Published 2025-03-18

Technologies: Fortinet FortiProxy SSL-VPN, Fortinet FortiOS, Fortinet FortiADC, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

An authentication bypass vulnerability in FortiOS and FortiProxy allows a remote unauthenticated attacker to gain super-admin privileges on downstream devices. Exploitation requires the Security Fabric to be enabled and the attacker to have prior knowledge of upstream and downstream device serial numbers to craft malicious CSF proxy requests.

Affected products

  • Fortinet FortiOS 7.0.0 through 7.0.16
  • Fortinet FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19

Timeline

  • 2025-02-11: disclosed: NVD Published Date
  • 2025-03-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-03-18: exploited: Reported as exploited in the wild per CISA KEV entry

Related threats