PT-2025-24716 · Fortinet · Fortios

Published

2025-06-10

·

Updated

2025-07-22

·

CVE-2025-24471

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions FortiOS versions 7.6.1 and below FortiOS versions 7.4.7 and below
Description The issue is related to an Improper Certificate Validation, which may allow an EAP verified remote user to connect from FortiClient via a revoked certificate.
Recommendations For FortiOS versions 7.6.1 and below, update to a version above 7.6.1 to resolve the issue. For FortiOS versions 7.4.7 and below, update to a version above 7.4.7 to resolve the issue. As a temporary workaround, consider restricting access to the EAP verified remote connection feature until a patch is available.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2025-12653
CVE-2025-24471

Affected Products

Fortios