Cookie Validation and Integrity Vulnerability in Fortinet FortiWeb Products
CVE-2025-64447
7.1HIGH
What is CVE-2025-64447?
The vulnerability stems from Fortinet FortiWeb's reliance on cookies without adequate validation and integrity checking. This flaw potentially enables unauthenticated attackers to execute arbitrary operations on the affected systems by sending specially crafted HTTP or HTTPS requests containing forged cookies. Exploiting this vulnerability may require prior knowledge of the FortiWeb serial number, heightening the risk of unauthorized access and system manipulation.
Affected Version(s)
FortiWeb 8.0.0 <= 8.0.1
FortiWeb 7.6.0 <= 7.6.5
FortiWeb 7.4.0 <= 7.4.10
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved