Security Advisory

CVE-2025-22251

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-06-10 16:36:12
Last updated 2025-06-10 19:40:04
Assigner fortinet
CVSS score 3.0
State PUBLISHED

Description

An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.