CVE-2025-49201: Critical severity Fortinet FortiPAM vulnerability
A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to execute unauthorized code or commands via specially crafted http requests
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49201?
CVE-2025-49201 is classified as a high-severity vulnerability due to its potential for unauthorized code execution.
How do I fix CVE-2025-49201?
To fix CVE-2025-49201, update Fortinet FortiPAM to version 1.5.1 or later and FortiSwitchManager to version 7.2.5 or later.
What versions are affected by CVE-2025-49201?
CVE-2025-49201 affects Fortinet FortiPAM versions 1.0.0 to 1.5.0 and FortiSwitchManager versions 7.2.0 to 7.2.4.
What type of vulnerability is CVE-2025-49201?
CVE-2025-49201 is a weak authentication vulnerability that can allow unauthorized access via crafted HTTP requests.
Can CVE-2025-49201 lead to data breaches?
Yes, CVE-2025-49201 can lead to data breaches as it allows attackers to execute unauthorized commands.