HIGH CISA KEV

CVE-2025-24472

CVSS v3

8.1

HIGH

EPSS Score

1.7%

exploit probability

CISA KEV

Yes

known exploited

Exploitation

SSVC status

Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.

CISA Known Exploited Vulnerability

Date Added
3/18/2025
Patch Due Date
4/8/2025
Ransomware Use
Known

Technical details

Published
2/11/2025

Frequently asked questions

What is CVE-2025-24472?

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.

Is CVE-2025-24472 actively exploited?

Yes. CVE-2025-24472 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 4/8/2025.

What is the CVSS score for CVE-2025-24472?

CVE-2025-24472 has a CVSS v3 base score of 8.1 (HIGH severity).

Is CVE-2025-24472 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.