CVE-2025-22256
published 2025-06-10CVE-2025-22256: A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3…
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.31%
22.9th percentile
A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through 1.4.1 allows attacker to improper access control via specially crafted HTTP requests
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortipam | — | — |
| fortinet | fortipam | — | — |
| fortinet | fortipam | — | — |
| fortinet | fortipam | >= 1.0.0 < 1.0.4 | 1.0.4 |
| fortinet | fortipam | 1.0.0 – 1.0.3 | — |
| fortinet | fortipam | >= 1.1.0 < 1.1.3 | 1.1.3 |
| fortinet | fortipam | 1.1.0 – 1.1.2 | — |
| fortinet | fortipam | >= 1.4.0 < 1.4.2 | 1.4.2 |
| fortinet | fortipam | 1.4.0 – 1.4.1 | — |
| fortinet | fortisra | — | — |
| fortinet | fortisra | >= 1.4.0 < 1.4.2 | 1.4.2 |
| fortinet | fortisra | 1.4.0 – 1.4.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5xp9-26pv-gh7v: A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1
ghsa_unreviewed·2025-06-10
CVE-2025-22256 [MEDIUM] CWE-280 GHSA-5xp9-26pv-gh7v: A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1
A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through 1.4.1 allows attacker to improper access control via specially crafted HTTP requests
Fortinet
A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1...
vendor_fortinet·2025-06-10·CVSS 6.3
CVE-2025-22256 [MEDIUM] CWE-280 A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1...
FG-IR-25-008: A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1...
A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through 1.4.1 allows attacker to improper access control via specially crafted HTTP requests
CVEs: CVE-2025-22256
CWEs: CWE-280
CVSS: 6.3 (medium)
Affected products: FortiPAM, FortiSRA, FortiSra, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-06-10
Published