CVE-2025-22251
published 2025-06-10CVE-2025-22251: An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.34%
25.7th percentile
An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 6.4.0 < 7.4.6 | 7.4.6 |
| fortinet | fortios | 6.4.0 – 6.4.16 | — |
| fortinet | fortios | 7.0.0 – 7.0.17 | — |
| fortinet | fortios | 7.2.0 – 7.2.11 | — |
| fortinet | fortios | 7.4.0 – 7.4.5 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Firewall session injection in FGSP
vendor_fortinet·2025-06-10·CVSS 3.1
CVE-2025-22251 [LOW] CWE-923 Firewall session injection in FGSP
FG-IR-24-287: Firewall session injection in FGSP
An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.
CVEs: CVE-2025-22251
CWEs: CWE-923
CVSS: 3.1 (low)
Affected products: FortiOS
GHSA
GHSA-mp2w-h9wf-5497: An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7
ghsa_unreviewed·2025-06-10
CVE-2025-22251 [LOW] CWE-923 GHSA-mp2w-h9wf-5497: An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7
An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-06-10
Published