CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2025-64471

MEDIUM
4.9
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-12-09
Last Modified2026-06-17
Data SourcesNVD

Vulnerability Description

A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to use the hash in place of the password to authenticate via crafted HTTP/HTTPS requests

Affected Platforms (CPE)

📦
Fortinet

Fortiweb

>= 7.0.0 and <= 7.0.11>= 7.2.0 and <= 7.2.11>= 7.4.0 and <= 7.4.10>= 7.6.0 and <= 7.6.4>= 8.0.0 and <= 8.0.1

References & Advisories

相關漏洞威脅