Improper restriction of communication channel to intended endpoints in FortiOS - CVE-2025-22251
Published: June 11, 2025
Vulnerability identifier: #VU111047
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-22251
CWE-ID: CWE-923
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
The vulnerability exists due to improper restriction of communication channel to intended endpoints in FGSP. An unauthenticated attacker can inject unauthorized sessions via crafted FGSP session synchronization packets.
Affected software
FortiOS
How to mitigate CVE-2025-22251
Install update from vendor's website.
FortiOS - addressed in versions 7.4.6, 7.6.1