CVE-2025-22251
An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an
Exploited
Not listed
EPSS
0.004
32.1th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jun 10, 2025
Assigned by fortinet
Description
An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.
Weakness: CWE-923
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS Check your version | Firewall / NGFW | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiOS
Credit
Internally discovered and reported by Greg Foletta of the Fortinet team.
Vendor remediation
Please upgrade to FortiOS version 7.6.1 or above Please upgrade to FortiOS version 7.4.6 or above