CVE-2025-24471

An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked cer

Severity
Medium 6
CVSS 3.1
Exploited
Not listed
EPSS
0.003
24.6th percentile
Discovered by
Not disclosed
Published
Jun 10, 2025
Assigned by fortinet

Description

An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.

Weakness: CWE-295

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Vendor-reported affected versions (2)
  • Fortinet · FortiOS
  • Siemens · RUGGEDCOM APE1808

Vendor remediation

Please upgrade to FortiOS version 7.6.2 or above Please upgrade to FortiOS version 7.4.8 or above Please upgrade to FortiSASE version 25.1.b or above