CVE-2025-25253

CWE-2974 documents4 sources
Severity
7.5HIGH
EPSS
0.0%
top 97.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14

Description

An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions ZTNA proxy may allow an unauthenticated attacker in a man-in-the middle position to intercept and tamper with connections to the ZTNA proxy

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages5 packages

NVDfortinet/fortiproxy7.0.07.4.9+1
CVEListV5fortinet/fortiproxy7.6.07.6.1+3
NVDfortinet/fortios7.0.07.4.9+1
CVEListV5fortinet/fortios7.6.07.6.2+3
CVEListV5fortinet/fortipam1.4.1

🔴Vulnerability Details

2
CVEList
CVE-2025-25253: An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 72025-10-14
GHSA
GHSA-9gmg-hfch-x94j: An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 72025-10-14

📋Vendor Advisories

1
Fortinet
ZTNA Server Improper Certificate Validation2025-10-14
CVE-2025-25253 (HIGH CVSS 7.5) | An Improper Validation of Certifica | cvebase.io