Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
高危 CISA KEV 在册
摘要
Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- Fortinet:Multiple Products
数据来源
- CISA KEV DATABASE
原始链接
- https://nvd.nist.gov/vuln/detail/CVE-2025-59718 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://fortiguard.fortinet.com/psirt/FG-IR-25-647 reference
- https://docs.fortinet.com/upgrade-tool/fortigate reference
时间线
- kev_added CISA KEV
- kev_ingest CISA KEV