CVE-2025-25253
An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions ZTNA proxy may allow an unauthenticated attacker in a man-in-the middle position to intercept and tamper with connections to the ZTNA proxy
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
- EPSS probability
- 0.11%
- CWE
- CWE-297
- Published
- 2025-10-14
- Last modified
- 2026-08-11
Affected products
- Fortinet FortiProxy
- Fortinet FortiProxy
- Fortinet FortiProxy
- Fortinet FortiProxy
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
Weakness type
Related vulnerabilities
- CVE-2020-11050 — Improper Validation of Certificate with Host Mismatch in Java-WebSocket
- CVE-2021-21385 — Disabled hostname verification and accepting self-signed certificates
- CVE-2025-3501 — Org.keycloak.protocol.services: keycloak hostname verification
- CVE-2018-10936 — A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check t
- CVE-2022-32153 — Splunk Enterprise lacked TLS host name validation
- CVE-2026-59638 — JSSE hostname verifier CN-fallback enabled by default despite documented opt-in
- CVE-2026-92943 — Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python
- CVE-2026-84197 — In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from