Vulnerability Details CVE-2025-59719
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
Exploit prediction scoring system (EPSS) score
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2025-59719
-
cpe:2.3:a:fortinet:fortiweb:7.4.0
-
cpe:2.3:a:fortinet:fortiweb:7.4.1
-
cpe:2.3:a:fortinet:fortiweb:7.4.2
-
cpe:2.3:a:fortinet:fortiweb:7.4.3
-
cpe:2.3:a:fortinet:fortiweb:7.4.4
-
cpe:2.3:a:fortinet:fortiweb:7.4.5
-
cpe:2.3:a:fortinet:fortiweb:7.4.6
-
cpe:2.3:a:fortinet:fortiweb:7.4.7
-
cpe:2.3:a:fortinet:fortiweb:7.4.8
-
cpe:2.3:a:fortinet:fortiweb:7.4.9
-
cpe:2.3:a:fortinet:fortiweb:7.6.0
-
cpe:2.3:a:fortinet:fortiweb:7.6.1
-
cpe:2.3:a:fortinet:fortiweb:7.6.2
-
cpe:2.3:a:fortinet:fortiweb:7.6.3
-
cpe:2.3:a:fortinet:fortiweb:7.6.4
-
cpe:2.3:a:fortinet:fortiweb:8.0.0