CVE-2025-22251
An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an
Severity
Low 3
CVSS 3.1
Exploited
Not listed
EPSS
0.004
34.2th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jun 10, 2025
Assigned by fortinet
Description
An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.
Weakness: CWE-923
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiOS
Credit
Internally discovered and reported by Greg Foletta of the Fortinet team.
Vendor remediation
Please upgrade to FortiOS version 7.6.1 or above Please upgrade to FortiOS version 7.4.6 or above