SSH key is added even if operation is aborted

Summary

An incomplete cleanup vulnerability [CWE-459] in FortiOS & FortiProxy may allow a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests.

Version Affected Solution
FortiOS 7.6 Not affected Not Applicable
FortiOS 7.4 Not affected Not Applicable
FortiOS 7.2 7.2 all versions Migrate to a fixed release
FortiOS 7.0 7.0 all versions Migrate to a fixed release
FortiOS 6.4 6.4 all versions Migrate to a fixed release
FortiOS 6.2 6.2 all versions Migrate to a fixed release
FortiProxy 7.6 Not affected Not Applicable
FortiProxy 7.4 Not affected Not Applicable
FortiProxy 7.2 7.2.0 through 7.2.2 Upgrade to 7.2.3 or above
FortiProxy 7.0 7.0.0 through 7.0.8 Upgrade to 7.0.9 or above
FortiProxy 2.0 2.0 all versions Migrate to a fixed release
FortiProxy 1.2 1.2 all versions Migrate to a fixed release
FortiProxy 1.1 1.1 all versions Migrate to a fixed release
Follow the recommended upgrade path using our tool at: https://docs.fortinet.com/upgrade-tool

Acknowledgement

Fortinet is pleased to thank Bobby Metz from Lumen Technologies for reporting this vulnerability under responsible disclosure.

Timeline

2025-06-10: Initial publication