Metrics
Affected Vendors & Products
Link | Providers |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-372 |
![]() ![]() |
Thu, 16 Oct 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Fortinet fortiproxy
|
|
CPEs | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Fortinet fortiproxy
|
Thu, 16 Oct 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 15 Oct 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Tue, 14 Oct 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiProxy 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0.1 through 7.0.21, and FortiOS 7.6.0 through 7.6.3 explicit web proxy may allow an authenticated proxy user to bypass the domain fronting protection feature via crafted HTTP requests. | |
First Time appeared |
Fortinet
Fortinet fortios |
|
Weaknesses | CWE-358 | |
CPEs | cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.1:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.2:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.3:*:*:*:*:*:*:* |
|
Vendors & Products |
Fortinet
Fortinet fortios |
|
References |
|

Status: PUBLISHED
Assigner: fortinet
Published: 2025-10-14T15:23:09.821Z
Updated: 2025-10-16T12:34:39.818Z
Reserved: 2025-02-05T13:31:18.867Z
Link: CVE-2025-25255

Updated: 2025-10-15T13:14:25.474Z

Status : Analyzed
Published: 2025-10-14T16:15:37.020
Modified: 2025-10-16T14:56:35.620
Link: CVE-2025-25255

No data.