Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Apr 8, 2025

CVE-2025-24472

High
EPSS 5.9%CISA KEVRansomware
Fortinet/FortiOS and FortiProxy

Description

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.

EPSS — Exploit Probability

5.9%

Higher than 90.4% of all CVEs

Required Action

https://fortiguard.fortinet.com/psirt/FG-IR-24-535 ; https://nvd.nist.gov/vuln/detail/CVE-2025-24472

Risk Assessment

HIGH
In CISA KEV
Ransomware

Details

Severity
High
EPSS
5.9%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Mar 18, 2025

Added to KEV

Mar 18, 2025

Remediation Due

Apr 8, 2025

Affected Product

Fortinet

FortiOS and FortiProxy

View all Fortinet CVEs