CVE-2025-54821
An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiO
Description
An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSASE 25.2.91 may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command.
Weakness: CWE-269
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
| Fortinet | FortiPAM | Identity / IAM / MFA | cna-assigner |
| Fortinet | FortiSASE | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (4)
- Fortinet · FortiPAM
- Fortinet · FortiSASE
- Fortinet · FortiOS
- Siemens · RUGGEDCOM APE1808
Vendor remediation
Fortinet remediated this issue in FortiSASE version 25.3.b and hence customers do not need to perform any action. Upgrade to FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.4 or above Upgrade to FortiOS version 7.4.12 or above Upgrade to FortiProxy version 7.6.4 or above Upgrade to upcoming FortiProxy version 7.4.14 or above Upgrade to FortiPAM version 1.7.0 or above Upgrade to FortiPAM version 1.6.1 or above