CVE-2025-49201

A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions

Severity
High 7.4
CVSS 3.1
Exploited
Not listed
EPSS
0.006
46.4th percentile
Discovered by
Vendor
Vendor advisory field
Published
Oct 14, 2025
Assigned by fortinet

Description

A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to execute unauthorized code or commands via specially crafted http requests

Weakness: CWE-1390

Affected products

Vendor Product Category Matched by
Fortinet FortiPAM Identity / IAM / MFA cna-assigner
Fortinet FortiSwitch Routing & Switching cna-assigner
Vendor-reported products (2)
  • Fortinet · FortiPAM
  • Fortinet · FortiSwitchManager

Credit

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security team.

Vendor remediation

Upgrade to FortiPAM version 1.6.0 or above Upgrade to FortiPAM version 1.5.1 or above Upgrade to FortiPAM version 1.4.3 or above Upgrade to FortiSwitchManager version 7.2.5 or above

Something wrong here?