PT-2025-24713 · Fortinet · Fortios

CVE-2025-22251

·

Publicado

2025-06-10

·

Atualizado

2025-07-25

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions FortiOS versions 6.4 through 7.6.0 FortiOS version 7.4.0 through 7.4.5
Description The issue is related to an improper restriction of communication channel to intended endpoints, which may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.
Recommendations For FortiOS versions 6.4 through 7.6.0, update to a version that includes the fix for this issue. For FortiOS version 7.4.0 through 7.4.5, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to FGSP session synchronization packets to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-12648
CVE-2025-22251

Produtos afetados

Fortios