7.5

CVE-2025-64471

A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to use the hash in place of the password to authenticate via crafted HTTP/HTTPS requests
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ Fortiweb Version >= 7.0.0 <= 7.0.11
Fortinet ≫ Fortiweb Version >= 7.2.0 <= 7.2.11
Fortinet ≫ Fortiweb Version >= 7.4.0 <= 7.4.10
Fortinet ≫ Fortiweb Version >= 7.6.0 <= 7.6.4
Fortinet ≫ Fortiweb Version >= 8.0.0 <= 8.0.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.262
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Fortinet 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CWE-836 Use of Password Hash Instead of Password for Authentication

The product records password hashes in a data store, receives a hash of a password from a client, and compares the supplied hash to the hash obtained from the data store.

https://fortiguard.fortinet.com/psirt/FG-IR-25-984
Vendor Advisory