CVE-2025-59719
BaseFortify
Publication date: 2025-12-09
Last updated on: 2025-12-09
Assigner: Fortinet, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fortinet | fortiweb | From 7.4.0 (inc) to 7.4.9 (inc) |
| fortinet | fortiweb | From 7.6.0 (inc) to 7.6.4 (inc) |
| fortinet | fortiweb | 8.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-347 | The product does not verify, or incorrectly verifies, the cryptographic signature for data. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an improper verification of cryptographic signatures in Fortinet FortiWeb versions 8.0.0, 7.6.0 through 7.6.4, and 7.4.0 through 7.4.9. It may allow an unauthenticated attacker to bypass the FortiCloud Single Sign-On (SSO) login authentication by using a crafted SAML response message.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability could bypass the FortiCloud SSO login authentication without needing to be authenticated. This could lead to unauthorized access with potentially full control, impacting confidentiality, integrity, and availability of the affected system.