CVE-2025-64447
BaseFortify
Publication date: 2025-12-09
Last updated on: 2025-12-09
Assigner: Fortinet, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fortinet | fortiweb | 7.2.3 |
| fortinet | fortiweb | 7.0.6 |
| fortinet | fortiweb | 7.6.0 |
| fortinet | fortiweb | 7.2.6 |
| fortinet | fortiweb | 7.0.9 |
| fortinet | fortiweb | 7.2.4 |
| fortinet | fortiweb | 7.0.1 |
| fortinet | fortiweb | 7.4.8 |
| fortinet | fortiweb | 7.2.2 |
| fortinet | fortiweb | 7.4.9 |
| fortinet | fortiweb | 7.2.8 |
| fortinet | fortiweb | 7.4.0 |
| fortinet | fortiweb | 7.2.0 |
| fortinet | fortiweb | 7.6.3 |
| fortinet | fortiweb | 7.4.10 |
| fortinet | fortiweb | 7.4.4 |
| fortinet | fortiweb | 7.0.0 |
| fortinet | fortiweb | 7.0.8 |
| fortinet | fortiweb | 7.2.9 |
| fortinet | fortiweb | 7.0.4 |
| fortinet | fortiweb | 7.6.4 |
| fortinet | fortiweb | 7.4.3 |
| fortinet | fortiweb | 7.0.2 |
| fortinet | fortiweb | 7.4.2 |
| fortinet | fortiweb | 7.4.7 |
| fortinet | fortiweb | 8.0.1 |
| fortinet | fortiweb | 7.6.5 |
| fortinet | fortiweb | 7.2.5 |
| fortinet | fortiweb | 7.2.1 |
| fortinet | fortiweb | 7.2.7 |
| fortinet | fortiweb | 7.0.5 |
| fortinet | fortiweb | 7.0.3 |
| fortinet | fortiweb | 7.4.5 |
| fortinet | fortiweb | 7.6.1 |
| fortinet | fortiweb | 7.6.2 |
| fortinet | fortiweb | 7.4.1 |
| fortinet | fortiweb | 7.0.10 |
| fortinet | fortiweb | 8.0.0 |
| fortinet | fortiweb | 7.2.10 |
| fortinet | fortiweb | 7.0.7 |
| fortinet | fortiweb | 7.2.11 |
| fortinet | fortiweb | 7.0.11 |
| fortinet | fortiweb | 7.4.6 |
| fortinet | fortiweb | From 7.0.0 (inc) to 7.0.11 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-565 | The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Fortinet FortiWeb versions 7.0.0 through 8.0.1 and involves a reliance on cookies without proper validation and integrity checking. An unauthenticated attacker who knows the FortiWeb serial number can craft HTTP or HTTPS requests with forged cookies to execute arbitrary operations on the system.
How can this vulnerability impact me? :
The vulnerability can allow an unauthenticated attacker to perform arbitrary operations on the affected FortiWeb system, potentially leading to full compromise of confidentiality, integrity, and availability of the system.