SecBoard
Zurück zur CVE-Übersicht

CVE-2025-24472

HIGH(8.1)KEV — Aktiv ausgenutzt

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Risk Signal Score52/100 — HOCH
  • CVSS 8.1 — Hoch
  • Im CISA KEV-Katalog (aktiv ausgenutzt)

Erwähnungen (letzte 60 Tage)

Artikel

CISA KEV

Bestätigt ausgenutzt

EPSS-Score

7.0%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

8.1

Technische Schwere

SecBoard-Einordnung

CVE-2025-24472 ist eine Schwachstelle vom Typ ' Using an Alternate Path or Channel' (CWE-288) in FortiOS (Versionen 7.0.0 bis 7.0.16) und FortiProxy (Versionen 7.2.0 bis 7.2.12 sowie 7.0.0 bis 7.0.19). Ein entfernter, nicht authentifizierter Angreifer kann bei aktiviertem Security Fabric und Kenntnis der Seriennummern von Upstream- und Downstream-Geräten Super-Admin-Rechte auf dem Downstream-Gerät erlangen, indem er manipulierte CSF-Proxy-Anfragen sendet.

KI-gestützte Einordnung auf Basis der NVD-Daten.

Beschreibung

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.

Referenzen