CVE-2025-24471
An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked cer
Severity
Medium 6
CVSS 3.1
Exploited
Not listed
EPSS
0.003
24.6th percentile
Discovered by
Not disclosed
Published
Jun 10, 2025
Assigned by fortinet
Description
An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.
Weakness: CWE-295
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
Vendor-reported affected versions (2)
- Fortinet · FortiOS
- Siemens · RUGGEDCOM APE1808
Vendor remediation
Please upgrade to FortiOS version 7.6.2 or above Please upgrade to FortiOS version 7.4.8 or above Please upgrade to FortiSASE version 25.1.b or above