CVE-2025-22256HIGH 8.8EPSS p21.8%
CVE-2025-22256CVE-2025-22256
Description
A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through 1.4.1 allows attacker to improper access control via specially crafted HTTP requests
Scoring
| CVSS 3.1 | 8.8 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.30% probability of exploitation · percentile 21.8% · 2026-06-19T12:03:05Z |
| Published | 2025-06-10 |
| Last modified | 2025-07-24 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Handling of Insufficient Permissions or Privilegescwe-280 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.