An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiProxy 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0.1 through 7.0.21, and FortiOS 7.6.0 through 7.6.3 explicit web proxy may allow an authenticated proxy user to bypass the domain fronting protection feature via crafted HTTP requests.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-24-372 |
![]() ![]() |
History
Tue, 14 Oct 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiProxy 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0.1 through 7.0.21, and FortiOS 7.6.0 through 7.6.3 explicit web proxy may allow an authenticated proxy user to bypass the domain fronting protection feature via crafted HTTP requests. | |
First Time appeared |
Fortinet
Fortinet fortios |
|
Weaknesses | CWE-358 | |
CPEs | cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.1:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.2:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:7.6.3:*:*:*:*:*:*:* |
|
Vendors & Products |
Fortinet
Fortinet fortios |
|
References |
|

Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-10-14T15:23:09.821Z
Reserved: 2025-02-05T13:31:18.867Z
Link: CVE-2025-25255

No data.

Status : Awaiting Analysis
Published: 2025-10-14T16:15:37.020
Modified: 2025-10-14T19:36:29.240
Link: CVE-2025-25255

No data.

No data.