CVE-2025-25253: Information disclosure in Fortinet FortiProxy
An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions ZTNA proxy may allow an unauthenticated attacker in a man-in-the middle position to intercept and tamper with connections to the ZTNA proxy
AI Analysis
Technical Summary
This vulnerability (CVE-2025-25253) is due to improper validation of certificates when there is a host mismatch in Fortinet FortiProxy versions 7.6.1 and below, 7.4.8 and below, all versions of 7.2 and 7.0, and FortiOS versions 7.6.2 and below, 7.4.8 and below, all versions of 7.2 and 7.0 ZTNA proxy. An unauthenticated attacker in a man-in-the-middle position could exploit this flaw to intercept and tamper with connections to the ZTNA proxy, potentially leading to information disclosure and manipulation of data in transit. The CVSS 3.1 vector indicates the attack requires adjacent network access with high attack complexity, no privileges or user interaction, and impacts confidentiality, integrity, and availability with partial exploit code maturity and a revised report confidence.
Potential Impact
An attacker with adjacent network access can intercept and modify traffic between clients and the ZTNA proxy due to improper certificate validation. This can lead to disclosure of sensitive information and tampering with data, impacting confidentiality, integrity, and availability of communications through the affected FortiProxy and FortiOS ZTNA proxy versions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Until a patch is available, organizations should consider network-level mitigations to prevent man-in-the-middle positioning and monitor for suspicious activity related to ZTNA proxy connections.
CVE-2025-25253: Information disclosure in Fortinet FortiProxy
Description
An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions ZTNA proxy may allow an unauthenticated attacker in a man-in-the middle position to intercept and tamper with connections to the ZTNA proxy
CVSS v3.1
Score 6.8medium
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2025-25253) is due to improper validation of certificates when there is a host mismatch in Fortinet FortiProxy versions 7.6.1 and below, 7.4.8 and below, all versions of 7.2 and 7.0, and FortiOS versions 7.6.2 and below, 7.4.8 and below, all versions of 7.2 and 7.0 ZTNA proxy. An unauthenticated attacker in a man-in-the-middle position could exploit this flaw to intercept and tamper with connections to the ZTNA proxy, potentially leading to information disclosure and manipulation of data in transit. The CVSS 3.1 vector indicates the attack requires adjacent network access with high attack complexity, no privileges or user interaction, and impacts confidentiality, integrity, and availability with partial exploit code maturity and a revised report confidence.
Potential Impact
An attacker with adjacent network access can intercept and modify traffic between clients and the ZTNA proxy due to improper certificate validation. This can lead to disclosure of sensitive information and tampering with data, impacting confidentiality, integrity, and availability of communications through the affected FortiProxy and FortiOS ZTNA proxy versions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Until a patch is available, organizations should consider network-level mitigations to prevent man-in-the-middle positioning and monitor for suspicious activity related to ZTNA proxy connections.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- fortinet
- Date Reserved
- 2025-02-05T13:31:18.867Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 68ee6cbb1b3029e3c7e0402f
Added to database: 10/14/2025, 15:31:07 UTC
Last enriched: 08/11/2026, 13:07:24 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 488
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.