Description
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.
In plain language
AI Act nowCVE-2025-24472 is a Fortinet FortiOS/FortiProxy flaw that can let an attacker bypass login and gain “super-admin” access on your system if your setup is reachable and the vulnerable path is enabled—this is already being used in real-world ransomware activity, so you should act now.
CVE-2025-24472 is an authentication bypass (CWE-288) in FortiOS and FortiProxy that allows a remote attacker with knowledge of upstream/downstream device serial numbers to gain super-admin privileges on a downstream device when the Security Fabric is enabled, via crafted CSF proxy requests; it is listed in CISA KEV with ransomware use.
What to do now
- Check whether you run FortiOS (7.0.0–7.0.16) and/or FortiProxy (7.2.0–7.2.12, 7.0.0–7.0.19) in your environment.
- If you are using affected versions, upgrade FortiOS to 7.0.17 or above.
- If you are using affected versions, upgrade FortiProxy to 7.2.13 or above (or to 7.0.20 or above).
- If you cannot upgrade immediately, follow the vendor’s PSIRT mitigation guidance and CISA guidance, and consider discontinuing use of the product until mitigations are in place.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
References
- Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFAen·Dark Reading· Exploited FortiOS Gunra
- US and South Korea warn of Gunra ransomware targeting govt agenciesen-us·BleepingComputer· Exploited FortiOS ransomware
- Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networksen·The Hacker News· Exploited FortiOS Gunra
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-24472 and every CVE in our database. Create a free account — no credit card required.
Create Free Account