VDB
GCVE-110-NCSC-2025-192
GCVE-110-NCSC-2025-192
Advisory PublishedCVSS 6.5/10
Fortinet heeft kwetsbaarheden verholpen in FortiOS.
Weaknesses (CWE)
CWE-295Improper Certificate ValidationCWE-613Insufficient Session ExpirationCWE-269Improper Privilege ManagementCWE-300Channel Accessible by Non-EndpointCWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-459Incomplete CleanupCWE-923Improper Restriction of Communication Channel to Intended EndpointsCWE-297Improper Validation of Certificate with Host MismatchCWE-1390Weak AuthenticationCWE-918Server-Side Request Forgery (SSRF)
Risk Scores
CVSS 3.1
6.5/10
Medium · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Fortinet | vers:semver/7.4.0|<=7.4.6 | — | — |
| Fortinet | vers:semver/1.1.0|<=1.1.6 | — | — |
| Fortinet | vers:semver/7.0.0|<=7.0.17 | — | — |
| Fortinet | vers:semver/7.4.0|<=7.4.7 | — | — |
| Fortinet | vers:fortinet/6.2.17 | — | — |
| Fortinet | vers:semver/7.2.0|<=7.2.14 | — | — |
| Fortinet | vers:unknown/7.4.0 | — | — |
| Fortinet | vers:semver/6.2.0|<=6.2.17 | — | — |
| Fortinet | vers:semver/1.2.0|<=1.2.13 | — | — |
| Fortinet | vers:fortinet/24.4.b | — | — |
| Fortinet | vers:fortinet/25.1.a.2 | — | — |
| Fortinet | vers:semver/7.6.0|<=7.6.1 | — | — |
| Fortinet | vers:semver/7.0.0|<=7.0.20 | — | — |
| Fortinet | vers:semver/7.2.0|<=7.2.4 | — | — |
| Fortinet | vers:fortinet/25.1.c | — | — |
| Fortinet | vers:semver/2.0.0|<=2.0.14 | — | — |
| Fortinet | vers:semver/7.2.0|<=7.2.6 | — | — |
| Fortinet | vers:semver/6.4.0|<=6.4.16 | — | — |
| Fortinet | vers:semver/7.0.0|<=7.0.14 | — | — |
| Fortinet | vers:semver/7.0.0|<=7.0.13 | — | — |
| Fortinet | vers:semver/7.2.0|<=7.2.11 | — | — |
Browse GCVE Records
73,873 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.