CVE-2025-24472
HIGH(8.1)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 8.1 — Hoch
- Im CISA KEV-Katalog (aktiv ausgenutzt)
Erwähnungen (letzte 60 Tage)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
7.0%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
8.1
Technische Schwere
SecBoard-Einordnung
CVE-2025-24472 ist eine Schwachstelle vom Typ 'Authentication Bypass Using an Alternate Path or Channel' (CWE-288) in FortiOS (Versionen 7.0.0 bis 7.0.16) und FortiProxy (Versionen 7.2.0 bis 7.2.12 sowie 7.0.0 bis 7.0.19). Ein entfernter, nicht authentifizierter Angreifer kann bei aktiviertem Security Fabric und Kenntnis der Seriennummern von Upstream- und Downstream-Geräten Super-Admin-Rechte auf dem Downstream-Gerät erlangen, indem er manipulierte CSF-Proxy-Anfragen sendet.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.