FortiPAM and FortiSwitch Manager Vulnerability Let Attackers Bypass Authentication Process
## Cybersecurity: Fortinet Product Vulnerability Advisory
Cybersecurity: Fortinet Product Vulnerability Advisory
Fortinet has released an advisory regarding a critical vulnerability in its FortiPAM and FortiSwitch Manager products. This flaw, identified as CVE-2025-49201, could permit attackers to bypass authentication using brute-force methods.
The vulnerability arises from a weak authentication mechanism in the Web Application Delivery (WAD) and Graphical User Interface (GUI) components, classified under CWE-1390. It possesses a CVSS v3.1 score of 7.4, indicating high severity. This could lead to unauthorized code execution or command injection, potentially enabling remote control over affected systems.
The issue impacts multiple versions of FortiPAM, Fortinet’s privileged access management solution, and certain releases of FortiSwitch Manager, responsible for network switch configurations.
FortiPAM: Versions 1.5.0, 1.4.0 through 1.4.2, and all versions of 1.3, 1.2, 1.1, and 1.0 are affected. FortiSwitch Manager: Versions 7.2.0 through 7.2.4 in the 7.2 series are impacted, while the 7.0 series remains unaffected.
Product Affected Versions Solution
FortiPAM 1.7 Not affected Not Applicable
FortiPAM 1.6 Not affected Not Applicable
Fortinet has released an advisory regarding a critical vulnerability in its FortiPAM and FortiSwitch Manager products.
FortiPAM 1.5 1.5.0 Upgrade to 1.5.1 or above
FortiPAM 1.4 1.4.0 through 1.4.2 Upgrade to 1.4.3 or above
FortiPAM 1.3 1.3 all versions Migrate to a fixed release
FortiPAM 1.2 1.2 all versions Migrate to a fixed release
FortiPAM 1.1 1.1 all versions Migrate to a fixed release
FortiPAM 1.0 1.0 all versions Migrate to a fixed release
FortiSwitch Manager 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above
FortiSwitch Manager 7.0 Not affected Not Applicable
Exploitation requires network access, and while no public exploits have been reported, persistent brute-force attempts could be employed. Fortinet recommends immediate patching to reduce risks. Users on vulnerable FortiPAM versions should update to the latest versions as indicated. FortiSwitch Manager 7.2 users should upgrade to version 7.2.5 or higher. Additionally, monitoring for unusual login attempts and implementing multi-factor authentication are advised as interim measures.
The vulnerability, discovered internally by Fortinet’s Product Security team, was formally published on Fri, Oct 14, 2025, under internal reference FG-IR-25-010.
This disclosure is part of ongoing efforts to address security concerns in network management tools.
Based on reporting by Cyber Security News.
