vulnerability
Fortinet FortiOS: Improper Restriction of Communication Channel to Intended Endpoints (CVE-2025-22251)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 3 | (AV:A/AC:M/Au:N/C:N/I:P/A:N) | Jul 28, 2025 | Jul 28, 2025 | Aug 11, 2025 |
Severity
3
CVSS
(AV:A/AC:M/Au:N/C:N/I:P/A:N)
Published
Jul 28, 2025
Added
Jul 28, 2025
Modified
Aug 11, 2025
Description
An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.
Solution
fortios-upgrade-7_4_6
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.