CVE-2025-24471: eap-cert-auth bypass via revoked certificate
An Improper Certificate Validation vulnerability [CWE-295] in FortiOS may allow an EAP verified remote user to connect from FortiClient via revoked certificate.
Other sources
An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.8 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.2 - Upgrade
Upgrade
FortiSASEto a version that resolves this vulnerability.Fixed in 25.1.b
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24471?
CVE-2025-24471 has been rated as a critical severity vulnerability due to its potential to allow unauthorized access through a revoked certificate.
How do I fix CVE-2025-24471?
To mitigate CVE-2025-24471, upgrade FortiOS to version 7.6.2 or 7.4.8 as applicable.
Which versions of FortiOS are affected by CVE-2025-24471?
CVE-2025-24471 affects FortiOS versions 7.6.1 and below, as well as versions 7.4.7 and below.
Can CVE-2025-24471 affect remote users?
Yes, CVE-2025-24471 specifically allows remote users to connect using a FortiClient via a revoked certificate.
Is there a workaround for CVE-2025-24471 if upgrades are not possible?
Currently, there are no known workarounds for CVE-2025-24471, so upgrading the affected FortiOS version is recommended.