Executive brief
A vulnerability in Fortinet's FortiOS operating system, specifically within the Single Sign-On (FSSO) Terminal Services Agent, could allow an authorized user to bypass firewall policies. By sending specifically crafted requests, a user who already has basic access to the system could gain unauthorized access to protected network resources. This could lead to internal security breaches or unauthorized data access within a corporate network.
Technical details
An Improper Verification of Source of a Communication Channel vulnerability (CWE-940) exists in the FortiOS FSSO Terminal Services Agent. The flaw allows an authenticated user with knowledge of FSSO policy configurations to bypass intended access controls. By sending crafted requests that exploit the lack of source verification, an attacker can gain unauthorized access to protected network segments. The attack requires local access and low privileges, but has a high complexity due to the requirement of specific configuration knowledge. Fortinet recommends upgrading to FortiOS 7.6.5 or 7.4.10 (upcoming) and updating the FSSO TS Agent to version 5.0 build 0324 or later.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.4, 7.4.0 through 7.4.9, 7.2 all versions, 7.0 all versions
- Siemens RUGGEDCOM APE1808 All versions with Fortinet NGFW < V7.4.10
Timeline
- 2026-02-10: disclosed: Initial publication by Fortinet
- 2026-02-10: advisory: Fortinet advisory FG-IR-25-384 published
- 2026-03-10: advisory: Siemens published advisory SSA-975644 for RUGGEDCOM APE1808