CVE-2025-59718
Summary
| CVE | CVE-2025-59718 |
|---|---|
| State | PUBLISHED |
| Assigner | fortinet |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-12-09 18:15:54 UTC |
| Updated | 2026-06-09 12:47:10 UTC |
| Description | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.658250000 probability, percentile 0.991690000 (date 2026-06-23)
CISA KEV: Listed on 2025-12-16; due 2025-12-23; ransomware use Unknown
Problem Types: CWE-347 | CWE-347 Improper access control
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA Known Exploited Vulnerability
| Vendor | Fortinet |
|---|---|
| Product | Multiple Products |
| Name | Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability |
| Required Action | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
| Notes | https://fortiguard.fortinet.com/psirt/FG-IR-25-647 ; https://docs.fortinet.com/upgrade-tool/fortigate ; https://nvd.nist.gov/vuln/detail/CVE-2025-59718 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fortinet | Fortiproxy | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Fortinet | FortiSwitchManager | affected 7.2.0 7.2.6 semver | Not specified |
| CNA | Fortinet | FortiSwitchManager | affected 7.0.0 7.0.5 semver | Not specified |
| CNA | Fortinet | FortiOS | affected 7.6.0 7.6.3 semver | Not specified |
| CNA | Fortinet | FortiOS | affected 7.4.0 7.4.8 semver | Not specified |
| CNA | Fortinet | FortiOS | affected 7.2.0 7.2.11 semver | Not specified |
| CNA | Fortinet | FortiOS | affected 7.0.0 7.0.17 semver | Not specified |
| CNA | Fortinet | FortiProxy | affected 7.6.0 7.6.3 semver | Not specified |
| CNA | Fortinet | FortiProxy | affected 7.4.0 7.4.10 semver | Not specified |
| CNA | Fortinet | FortiProxy | affected 7.2.0 7.2.14 semver | Not specified |
| CNA | Fortinet | FortiProxy | affected 7.0.0 7.0.21 semver | Not specified |
| ADP | Siemens | RUGGEDCOM APE1808 | affected * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cert-portal.siemens.com/productcert/html/ssa-864900.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | Third Party Advisory |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| fortiguard.fortinet.com/psirt/FG-IR-25-647 | [email protected] | fortiguard.fortinet.com | Vendor Advisory |
| arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-foll... | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | arcticwolf.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2025-12-16T00:00:00.000Z | CVE-2025-59718 added to CISA KEV |
Solutions
CNA: Upgrade to FortiSwitchManager version 7.2.7 or above Upgrade to FortiSwitchManager version 7.0.6 or above Upgrade to FortiProxy version 7.6.4 or above Upgrade to FortiProxy version 7.4.11 or above Upgrade to FortiProxy version 7.2.15 or above Upgrade to FortiProxy version 7.0.22 or above Upgrade to FortiOS version 7.6.4 or above Upgrade to FortiOS version 7.4.9 or above Upgrade to FortiOS version 7.2.12 or above Upgrade to FortiOS version 7.0.18 or above Upgrade to FortiWeb version 8.0.1 or above Upgrade to FortiWeb version 7.6.5 or above Upgrade to FortiWeb version 7.4.10 or above Fortinet remediated this issue in FortiSASE version 25.3.b and hence customers do not need to perform any action. Upgrade to FortiPAM version 1.8.0 or above