eap-cert-auth bypass via revoked certificate

Summary

An Improper Certificate Validation vulnerability [CWE-295] in FortiOS may allow an EAP verified remote user to connect from FortiClient via revoked certificate.

Version Affected Solution
FortiOS 7.6 7.6.0 through 7.6.1 Upgrade to 7.6.2 or above
FortiOS 7.4 7.4.0 through 7.4.7 Upgrade to 7.4.8 or above
FortiOS 7.2 Not affected Not Applicable
FortiOS 7.0 Not affected Not Applicable
FortiOS 6.4 Not affected Not Applicable
FortiSASE 25.1.a 25.1.a.2 Migrate to a fixed release
FortiSASE 24.4 Not affected Not Applicable
FortiSASE 23.3 Not affected Not Applicable
FortiSASE 23.2 Not affected Not Applicable
FortiSASE 23.1 Not affected Not Applicable
FortiSASE 22.4 Not affected Not Applicable
Follow the recommended upgrade path using our tool at: https://docs.fortinet.com/upgrade-tool

Acknowledgement

Fortinet is pleased to thank Rhys H & Adam L from CGI UK for reporting this vulnerability under responsible disclosure.

Timeline

2025-06-10: Initial publication