Siemens ProductCERT segnala due vulnerabilità in FortiOS: CVE-2025-55018 e CVE-2025-62439. CVE-2025-55018 permette HTTP request smuggling che può eludere il logging del firewall. CVE-2025-62439 permette a utenti autenticati con conoscenza FSSO accesso non autorizzato a risorse protette.
Part of the PlainSec briefing for 2026-03-10
Every edition of this story: FortiOS Permette Bypass dei Log e Accesso a Reti Protette