PT-2025-28464 · Fortinet · Fortiproxy+1

Published

2025-07-08

·

Updated

2025-07-22

·

CVE-2024-55599

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: FortiOS versions prior to 7.4.8 FortiOS version 7.6.0 FortiOS versions 7.0 and earlier FortiOS versions 6.4 and earlier FortiProxy versions prior to 7.4.9 FortiProxy versions 7.2 and earlier FortiProxy versions 7.0 and earlier FortiProxy version 7.6.1 and earlier
Description: The issue is related to an improperly implemented security check, allowing a remote unauthenticated user to bypass the DNS filter via Apple devices.
Recommendations: For FortiOS version 7.6.0, update to a version that includes the security fix. For FortiOS versions 7.4.7 and below, update to version 7.4.8 or later. For FortiOS versions 7.0 and earlier, update to a version that includes the security fix. For FortiOS versions 6.4 and earlier, update to a version that includes the security fix. For FortiProxy version 7.6.1 and earlier, update to a version that includes the security fix. For FortiProxy versions 7.4.8 and below, update to version 7.4.9 or later. For FortiProxy versions 7.2 and earlier, update to a version that includes the security fix. For FortiProxy versions 7.0 and earlier, update to a version that includes the security fix.

Fix

Improperly Implemented Security Check for Standard

Weakness Enumeration

Related Identifiers

BDU:2025-09543
CVE-2024-55599

Affected Products

Fortios
Fortiproxy