IM
IronMonkey Threat Research

CVE-2025-59719 CRITICAL

Published: 2025-12-09 | Last Modified: 2026-06-09 | Status: Modified

Description

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

Additional Descriptions (1)

Una vulnerabilidad de verificación impropia de firma criptográfica en Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 hasta 7.6.4, FortiWeb 7.4.0 hasta 7.4.9 puede permitir a un atacante no autenticado eludir la autenticación de inicio de sesión de FortiCloud SSO a través de un mensaje de respuesta SAML manipulado.

CVSS Metrics

Base Score: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Secondary

Exploitability Score: 3.9

Impact Score: 5.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-347

Affected Products

Vendor Product Version Update Type
fortinet fortiweb * <built-in method update of dict object at 0x7d1e64bc92c0> Application
fortinet fortiweb * <built-in method update of dict object at 0x7d1e6c96d140> Application
fortinet fortiweb 8.0.0 <built-in method update of dict object at 0x7d1e5feca9c0> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortiweb:8.0.0:*:*:*:*:*:*:*
Notification
Message here