CVE-2025-22251

An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

History

25 Jul 2025, 15:26

Type Values Removed Values Added
CPE cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:*
References () https://fortiguard.fortinet.com/psirt/FG-IR-24-287 - () https://fortiguard.fortinet.com/psirt/FG-IR-24-287 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
First Time Fortinet
Fortinet fortios

10 Jun 2025, 17:21

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-10 17:21

Updated : 2025-07-25 15:26


NVD link : CVE-2025-22251

Mitre link : CVE-2025-22251


JSON object : View

Products Affected

fortinet

  • fortios
CWE
CWE-923

Improper Restriction of Communication Channel to Intended Endpoints