cbcvebase.
CVE-2025-22256
published 2025-06-10

CVE-2025-22256: A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through 1.4.1 allows attacker to improper access control via specially crafted HTTP requests

Affected

13 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortipam
fortinetfortipam
fortinetfortipam
fortinetfortipam>= 1.0.0 < 1.0.41.0.4
fortinetfortipam1.0.0 – 1.0.3
fortinetfortipam>= 1.1.0 < 1.1.31.1.3
fortinetfortipam1.1.0 – 1.1.2
fortinetfortipam>= 1.4.0 < 1.4.21.4.2
fortinetfortipam1.4.0 – 1.4.1
fortinetfortisra
fortinetfortisra>= 1.4.0 < 1.4.21.4.2
fortinetfortisra1.4.0 – 1.4.1