CVE-2025-24472

high

Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.

References

https://www.infosecurity-magazine.com/news/gunra-ransomware-fortinet-flaws/

https://www.hipaajournal.com/gunra-ransomware/

https://www.databreachtoday.com/alert-unpatched-fortinet-devices-fall-to-gunra-ransomware-a-32518

https://www.darkreading.com/cyberattacks-data-breaches/gunra-ransomware-gang-fortinet-flaws-bypasses-mfa

https://www.bleepingcomputer.com/news/security/us-warns-of-gunra-ransomware-attacks-against-government-critical-infrastructure/

https://thehackernews.com/2026/08/gunra-ransomware-exploits-fortinet-and.html

https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a

https://therecord.media/ransomware-south-korea-fbi-gunra

https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates

https://www.darkreading.com/cyberattacks-data-breaches/fortinet-products-in-crosshairs-again

https://securityaffairs.com/178736/hacking/attackers-exploit-fortinet-flaws-to-deploy-qilin-ransomware.html

https://www.bleepingcomputer.com/news/security/critical-fortiswitch-flaw-lets-hackers-change-admin-passwords-remotely/

https://thehackernews.com/2025/03/vanhelsing-raas-launch-3-victims-5k.html

https://www.databreachtoday.com/fortinet-targeting-ransomware-attacks-leave-devices-patched-a-27800

https://www.darkreading.com/cyberattacks-data-breaches/critical-fortinet-vulnerability-draws-fresh-attention

https://securityaffairs.com/175583/security/u-s-cisa-adds-fortinet-fortios-fortiproxy-and-github-action-flaws-to-its-known-exploited-vulnerabilities-catalog.html

https://www.cisa.gov/news-events/alerts/2025/03/18/cisa-adds-two-known-exploited-vulnerabilities-catalog

https://therecord.media/mora001-ransomware-gang-exploiting-vulnerability-lockbit

https://www.theregister.com/2025/03/14/ransomware_gang_lockbit_ties/

https://www.darkreading.com/cyberattacks-data-breaches/actor-tied-lockbit-ransomware-targets-fortinet-users

https://www.bleepingcomputer.com/news/security/new-superblack-ransomware-exploits-fortinet-auth-bypass-flaws/

https://www.forescout.com/blog/new-ransomware-operator-exploits-fortinet-vulnerability-duo/

Details

Source: Mitre, NVD

Published: 2025-02-11

Updated: 2026-08-05

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 8.1

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.07945