Executive brief
A security vulnerability exists in several Fortinet networking and access management products, including FortiOS and FortiProxy. This flaw could allow an administrator who already has high-level access to bypass security restrictions that normally limit which specific computers or networks are allowed to manage the device. While the risk is low because it requires existing administrative credentials, it could allow a malicious insider to perform management tasks from unauthorized locations.
Technical details
An Improper Privilege Management vulnerability (CWE-269) exists in the Command Line Interface (CLI) of multiple Fortinet products. The flaw allows an authenticated user with administrative privileges to bypass 'trusted host' security policies, which are intended to restrict management access to specific IP addresses or ranges. By executing a specially crafted CLI command, an attacker can circumvent these source-based access controls. The vulnerability affects FortiOS (6.4 through 7.6.3), FortiPAM (1.0 through 1.6.0), and FortiProxy (7.0 through 7.6.3). Siemens has also identified impact on RUGGEDCOM APE1808 devices running Fortinet NGFW, recommending an update to version 7.6.6 or later.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions
- Fortinet FortiPAM 1.0 through 1.6.0
- Fortinet FortiProxy 7.0 through 7.4 all versions, 7.6.0 through 7.6.3
- Siemens RUGGEDCOM APE1808 All versions with Fortinet NGFW < V7.6.6
Timeline
- 2025-11-18: disclosed: Initial publication by Fortinet
- 2025-11-18: advisory: NVD published date
- 2025-05-13: advisory: Siemens published related advisory SSA-864900