{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-11T20:55:13.475","vulnerabilities":[{"cve":{"id":"CVE-2025-24471","sourceIdentifier":"psirt@fortinet.com","published":"2025-06-10T17:21:16.277","lastModified":"2025-07-22T17:57:19.240","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate."},{"lang":"es","value":"Una vulnerabilidad de validación de certificado incorrecta [CWE-295] en FortiOS versión 7.6.1 y anteriores, versión 7.4.7 y anteriores puede permitir que un usuario remoto verificado por EAP se conecte desde FortiClient a través de un certificado revocado."}],"metrics":{"cvssMetricV31":[{"source":"psirt@fortinet.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"psirt@fortinet.com","type":"Secondary","description":[{"lang":"en","value":"CWE-295"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortisase:25.1.39:*:*:*:-:*:*:*","matchCriteriaId":"77B84900-E96D-4E2C-8797-B1460E71874E"},{"vulnerable":true,"criteria":"cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*","versionStartIncluding":"7.4.0","versionEndExcluding":"7.4.8","matchCriteriaId":"26515743-5A9A-4885-A08E-535E4ABE0153"},{"vulnerable":true,"criteria":"cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*","versionStartIncluding":"7.6.0","versionEndExcluding":"7.6.2","matchCriteriaId":"8563B77B-03AB-4ED2-BE70-DCF636FE0B60"}]}]}],"references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-24-544","source":"psirt@fortinet.com","tags":["Vendor Advisory"]}]}}]}