CVE-2025-68482: Lack of TLS Certificate Validation during initial SSO Authentication
A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to view confidential information via a man in the middle [MiTM] attack.
Other sources
An improper certificate validation [CWE-295] vulnerability in the FortiManager GUI may allow a remote unauthenticated attacker to view confidential information via a man in the middle [MiTM] attack.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68482?
The severity of CVE-2025-68482 is critical due to the lack of TLS certificate validation, which could allow an attacker to conduct man-in-the-middle attacks.
How do I fix CVE-2025-68482?
To fix CVE-2025-68482, upgrade Fortinet FortiAnalyzer and FortiManager to version 7.6.5 or 7.4.9 or higher.
Which versions are affected by CVE-2025-68482?
CVE-2025-68482 affects Fortinet FortiAnalyzer versions 7.6.0 to 7.6.4, 7.4.0 to 7.4.8, and earlier versions down to 6.4.
Are there any workarounds for CVE-2025-68482?
There are no known workarounds for CVE-2025-68482, and upgrading to the latest patched versions is recommended.
What products are impacted by CVE-2025-68482?
CVE-2025-68482 impacts Fortinet FortiAnalyzer and FortiManager across multiple versions.