Update 2/11/25 07:32 PM ET: After publishing our story, Fortinet has informed us that the new CVE-2025-24472 flaw added to FG-IR-24-535 today is not a zero-day and was already fixed in January. Furthermore, even though today's updated advisory indicates that both flaws were exploited in attacks and even includes a workaround for the new CSF proxy requests exploitation pathway, Fortinet says that only CVE-2024-55591 was exploited. Fortinet told BleepingComputer that if a customer previously upgraded based on the guidance in FG-IR-24-535 / CVE-2024-55591, then they are already protected against the newly disclosed vulnerability. The title of our story has been updated to reflect this new information, and our original article is below. Fortinet warned today that attackers are exploiting another now-patched zero-day bug in FortiOS and FortiProxy to hijack Fortinet firewalls and breach enterprise networks. Successful exploitation of this authentication bypass vulnerability (CVE-2025-24472) allows remote attackers to gain super-admin privileges by making maliciously crafted CSF proxy requests. The security flaw impacts FortiOS 7.0.0 through 7.0.16, FortiProxy 7.0.0 through 7.0.19, and FortiProxy 7.2.0 through 7.2.12. Fortinet fixed it in FortiOS 7.0.17 or above and FortiProxy 7.0.20/7.2.13 or above. Fortinet added the bug as a new CVE-ID to a security advisory issued last month cautioning customers that threat actors were exploiting a zero-day vulnerability in FortiOS and FortiPro...
Fortinet discloses second firewall auth bypass patched in January
BleepingComputer
·Sergiu Gatlan
·Published Feb 11, 2025
·Updated
Affected Software
8 affected components
Fortinet FortiOS=7.0.0
Fortinet FortiOS=7.0.16
Fortinet FortiProxy=7.0.0
Fortinet FortiProxy=7.0.19
Fortinet FortiProxy=7.2.0
Fortinet FortiProxy=7.2.12
Fortinet FortiOS
Fortinet FortiProxy
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a newly disclosed vulnerability in Fortinet firewalls that was patched in January.
2
What security implications are discussed?
The vulnerability allows for an authentication bypass, potentially compromising firewall security.
3
What products or software are affected?
The affected products include Fortinet FortiOS and FortiProxy versions 7.0.0, 7.0.16, 7.0.19, and 7.2.0, 7.2.12.
4
Has this vulnerability been active since it was disclosed?
No, Fortinet clarified that the vulnerability was not a zero-day and had already been fixed in January.
5
What is the CVE associated with this vulnerability?
The vulnerability is identified as CVE-2025-24472.