IM
IronMonkey Threat Research

CVE-2025-24471 MEDIUM

Published: 2025-06-10 | Last Modified: 2026-06-09 | Status: Modified

Description

An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.

Additional Descriptions (1)

Una vulnerabilidad de validación de certificado incorrecta [CWE-295] en FortiOS versión 7.6.1 y anteriores, versión 7.4.7 y anteriores puede permitir que un usuario remoto verificado por EAP se conecte desde FortiClient a través de un certificado revocado.

CVSS Metrics

Base Score: 6.5 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactHIGH
Availability ImpactNONE

Source: [email protected]

Type: Secondary

Exploitability Score: 2.8

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-295

Affected Products

Vendor Product Version Update Type
fortinet fortisase 25.1.39 <built-in method update of dict object at 0x7d1e5fec8500> Application
fortinet fortios * <built-in method update of dict object at 0x7d1e5da50440> Operating System
fortinet fortios * <built-in method update of dict object at 0x7d1e5fec86c0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:fortinet:fortisase:25.1.39:*:*:*:-:*:*:*
Yes cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Notification
Message here