Vulnerability Details CVE-2025-24471
An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 6.4%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2025-24471
-
cpe:2.3:a:fortinet:fortisase:25.1.39
-
cpe:2.3:o:fortinet:fortios:7.4.0
-
cpe:2.3:o:fortinet:fortios:7.4.1
-
cpe:2.3:o:fortinet:fortios:7.4.2
-
cpe:2.3:o:fortinet:fortios:7.4.3
-
cpe:2.3:o:fortinet:fortios:7.4.4
-
cpe:2.3:o:fortinet:fortios:7.4.5
-
cpe:2.3:o:fortinet:fortios:7.4.6
-
cpe:2.3:o:fortinet:fortios:7.4.7
-
cpe:2.3:o:fortinet:fortios:7.6.0
-
cpe:2.3:o:fortinet:fortios:7.6.1