CVE-2025-22251

An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an

Severity
Low 3
CVSS 3.1
Exploited
Not listed
EPSS
0.004
34.2th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jun 10, 2025
Assigned by fortinet

Description

An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.

Weakness: CWE-923

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiOS

Credit

Internally discovered and reported by Greg Foletta of the Fortinet team.

Vendor remediation

Please upgrade to FortiOS version 7.6.1 or above Please upgrade to FortiOS version 7.4.6 or above

Something wrong here?