CVE-2025-24471

An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked cer

Severity
Medium 6
CVSS 3.1
Exploited
Not listed
EPSS
0.004
31.3th percentile
Discovered by
Third party
Vendor advisory field
Published
Jun 10, 2025
Assigned by fortinet

Description

An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.

Weakness: CWE-295

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Vendor-reported products (2)
  • Fortinet · FortiOS
  • Siemens · RUGGEDCOM APE1808

Credit

Fortinet is pleased to thank Rhys H & Adam L from CGI UK for reporting this vulnerability under responsible disclosure.

Vendor remediation

Please upgrade to FortiOS version 7.6.2 or above Please upgrade to FortiOS version 7.4.8 or above Please upgrade to FortiSASE version 25.1.b or above

Something wrong here?