4.2
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:F/RL:X/RC:C
Description
An improper authorization vulnerability [CWE-285] in Fortinet FortiOS version 7.4.0 through 7.4.1 and before 7.2.8 & Fortinet FortiProxy before version 7.4.8 allows an authenticated attacker to access static files of others VDOMs via crafted HTTP or HTTPS requests.
Basic Information
ID
CVE-2025-54822
Source
fortinet
Published
Oct 14, 2025 at 15:23
Affected Product
Vendor
Fortinet
Product
FortiProxy
Version
7.4.0
Affected Versions
Fortinet FortiProxy 7.4.0
Fortinet FortiProxy 7.2.0
Fortinet FortiProxy 7.0.0
Fortinet FortiProxy 2.0.0
Fortinet FortiOS 7.4.0
Fortinet FortiOS 7.2.0
Fortinet FortiOS 7.0.0
Fortinet FortiProxy 7.2.0
Fortinet FortiProxy 7.0.0
Fortinet FortiProxy 2.0.0
Fortinet FortiOS 7.4.0
Fortinet FortiOS 7.2.0
Fortinet FortiOS 7.0.0