CVE-2025-59718
CRITICAL(9.8)KEVWahrscheinlich ausgenutzt
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Beschreibung
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
KEV-Informationen
CVSS-Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnenCWEs
Betroffene Produkte
| Hersteller | Produkt | Version |
|---|---|---|
| fortinet | fortiproxy | >= 7.0.0, < 7.0.22; >= 7.2.0, < 7.2.15; >= 7.4.0, < 7.4.11; >= 7.6.0, < 7.6.4 |
| fortinet | fortiswitchmanager | >= 7.0.0, < 7.0.6; >= 7.2.0, < 7.2.7 |
| fortinet | fortios | >= 7.0.0, < 7.0.18; >= 7.2.0, < 7.2.12; >= 7.4.0, < 7.4.9; >= 7.6.0, < 7.6.4 |
| siemens | ruggedcom ape1808 firmware | - |
Referenzen
- https://fortiguard.fortinet.com/psirt/FG-IR-25-647(Vendor Advisory)
- https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/(Third Party Advisory)
- https://cert-portal.siemens.com/productcert/html/ssa-864900.html(Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59718(US Government Resource)
Hilfe beim Schwachstellenmanagement?
Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.