A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 may allow an attacker with knowledge of an existing admin account to access the device as a valid admin via an authentication bypass.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-472 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
04 Jun 2025, 14:35
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiswitchmanager:7.2.5:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:7.6.0:*:*:*:*:*:*:* |
|
First Time |
Fortinet
Fortinet fortiswitchmanager Fortinet fortios Fortinet fortiproxy |
|
References | () https://fortiguard.fortinet.com/psirt/FG-IR-24-472 - Vendor Advisory |
28 May 2025, 15:01
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
28 May 2025, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-28 08:15
Updated : 2025-06-04 14:35
NVD link : CVE-2025-22252
Mitre link : CVE-2025-22252
CVE.ORG link : CVE-2025-22252
JSON object : View
Products Affected
fortinet
- fortios
- fortiproxy
- fortiswitchmanager
CWE
CWE-306
Missing Authentication for Critical Function