FG-IR-25-545: Trusted hosts bypass via SSH
An Improper Privilege Management vulnerability [CWE-269] in FortiOS, FortiProxy and FortiPAM may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-25-545?
The severity of FG-IR-25-545 is classified as a significant risk due to improper privilege management allowing bypass of the trusted host policy.
How do I fix FG-IR-25-545?
To fix FG-IR-25-545, upgrade to FortiOS version 7.6.4 or higher, or apply the recommended patches for FortiPAM and FortiProxy as applicable.
Which Fortinet products are affected by FG-IR-25-545?
FortiOS, FortiProxy, and FortiPAM are the affected products under vulnerability FG-IR-25-545.
What happens if FG-IR-25-545 is exploited?
Exploitation of FG-IR-25-545 may allow an authenticated administrator to bypass security checks, potentially leading to unauthorized access to sensitive functions.
What versions are vulnerable to FG-IR-25-545?
Versions of FortiOS prior to 7.6.4, and specific older versions of FortiPAM and FortiProxy are vulnerable to FG-IR-25-545.