Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-49201


A weak authentication in Fortinet FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to execute unauthorized code or commands via specially crafted http requests


Published

2025-10-14T16:15:38.840

Last Modified

2025-10-15T17:18:16.820

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-1390

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System fortinet fortipam < 1.4.3 Yes
Operating System fortinet fortipam 1.5.0 Yes
Application fortinet fortiswitchmanager < 7.2.5 Yes

References