Home

Description

An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an attacker who has already gained access to a victim's user account to reset the account credentials without being prompted for the account's password

PUBLISHED Reserved 2025-09-22 | Published 2025-12-09 | Updated 2025-12-09 | Assigner fortinet




MEDIUM: 6.5CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H/E:H/RL:O/RC:C

Problem types

Improper access control

Product status

Default status
unaffected

7.6.0 (semver)
affected

7.5.0 (semver)
affected

7.4.0 (semver)
affected

7.3.0 (semver)
affected

Default status
unaffected

7.6.0 (semver)
affected

7.5.0 (semver)
affected

7.4.0 (semver)
affected

7.3.0 (semver)
affected

References

fortiguard.fortinet.com/psirt/FG-IR-25-599

cve.org (CVE-2025-59808)

nvd.nist.gov (CVE-2025-59808)

Download JSON