A weak authentication in Fortinet FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to execute unauthorized code or commands via specially crafted http requests
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Upgrade to FortiPAM version 1.6.0 or above Upgrade to FortiPAM version 1.5.1 or above Upgrade to FortiPAM version 1.4.3 or above Upgrade to FortiSwitchManager version 7.2.5 or above
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-25-010 |
![]() ![]() |
History
Tue, 14 Oct 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A weak authentication in Fortinet FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to execute unauthorized code or commands via specially crafted http requests | |
First Time appeared |
Fortinet
Fortinet fortipam |
|
Weaknesses | CWE-1390 | |
CPEs | cpe:2.3:o:fortinet:fortipam:1.0.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:1.0.1:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:1.0.2:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:1.0.3:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:1.1.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:1.1.1:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:1.1.2:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:1.2.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:1.3.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:1.3.1:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:1.4.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:1.4.1:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:1.4.2:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:1.5.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Fortinet
Fortinet fortipam |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-10-14T15:22:44.720Z
Reserved: 2025-06-03T07:46:08.521Z
Link: CVE-2025-49201

No data.

Status : Undergoing Analysis
Published: 2025-10-14T16:15:38.840
Modified: 2025-10-14T19:36:29.240
Link: CVE-2025-49201

No data.

No data.