← Back

CVE-2025-59718

nvd nist
Published: Dec 9, 2025Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: psirt@fortinet.com (Secondary)

Description

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

Affected (11)

3 products
Fortios
Fortiproxy
Fortiswitchmanager
1 product
Ruggedcom Ape1808 Firmware
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 7.0.0 to 7.0.18
From 7.2.0 to 7.2.12
From 7.4.0 to 7.4.9
From 7.6.0 to 7.6.4
Fortinet
From 7.0.0 to 7.0.22
From 7.2.0 to 7.2.15
From 7.4.0 to 7.4.11
From 7.6.0 to 7.6.4
Fortinet
From 7.0.0 to 7.0.6
From 7.2.0 to 7.2.7
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Ruggedcom Ape1808
All versions

References (4)

Source: psirt@fortinet.com
Vendor Advisory
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.