CVE-2025-62439: Firewall policy bypass in FSSO Terminal Services Agent
An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] in FortiOS FSSO Terminal Services Agent may allow an authenticated user with knowledge of FSSO policy configurations to gain unauthorized access to protected network resources via crafted requests.
Other sources
An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions may allow an authenticated user with knowledge of FSSO policy configurations to gain unauthorized access to protected network resources via crafted requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62439?
CVE-2025-62439 is classified as a high severity vulnerability due to its potential to allow unauthorized access to protected resources.
How do I fix CVE-2025-62439?
To mitigate CVE-2025-62439, update FortiOS to version 7.6.5 or later, or apply the appropriate patches if available for affected versions.
Who is affected by CVE-2025-62439?
Organizations using FortiOS versions 7.6.0 to 7.6.4, 7.4.0 to 7.4.9, and certain 7.2 and 7.0 versions are at risk from CVE-2025-62439.
What type of vulnerability is CVE-2025-62439?
CVE-2025-62439 is categorized as an Improper Verification of Source of a Communication Channel vulnerability, which can lead to policy bypass.
Can authenticated users exploit CVE-2025-62439?
Yes, authenticated users knowledgeable about the FSSO policy configurations can exploit CVE-2025-62439 to gain unauthorized access.