- Description
- An Improper Privilege Management vulnerability [CWE-269] affecting Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16 and before 6.4.15, FortiProxy version 7.6.0 through 7.6.1 and before 7.4.7 & FortiWeb version 7.6.0 through 7.6.1 and before 7.4.6 allows an authenticated attacker with at least read-only admin permissions to gain super-admin privileges via crafted requests to Node.js websocket module.
- Source
- psirt@fortinet.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 6.6
- Impact score
- 5.9
- Exploitability score
- 0.7
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
- Severity
- MEDIUM
- psirt@fortinet.com
- CWE-269
- Hype score
- Not currently trending
⚠️Actualizaciones de seguridad de Fortinet ❗CVE-2023-42788 ❗CVE-2025-22254 ❗CVE-2025-22862 ➡️Más info: https://t.co/6QMLOS6glh https://t.co/9WQAHPzv0d
@CERTpy
18 Jun 2025
149 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-22254 An Improper Privilege Management vulnerability [CWE-269] affecting Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 thro… https://t.co/6HIL58pzee
@CVEnew
10 Jun 2025
224 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes