<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Capacity to forge authentication cookies</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-25-945</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2025-12-09T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2025-12-09T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2025-12-09T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            A reliance on cookie without validation or integrity checking vulnerability [CWE-565] in FortiWeb may allow an unauthenticated attacker to execute arbitrary operations on the system via crafted HTTP or HTTPS request via forged cookies requiring knowledge of the FortiWeb serial number.FortiAppSec Cloud is NOT impacted by this vulnerability.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Escalation of privilege
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="4">
            None
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Internally discovered by Fortiweb development team.</cvrf:Description>
        </cvrf:Acknowledgment>
        <cvrf:Acknowledgment>
            <cvrf:Description>Fortinet is also pleased to thank Jason McFadyen of Trend Research for reporting this vulnerability under responsible disclosure.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiWeb" Type="Product Name">
                <Branch Name="8.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-8.0.1">FortiWeb 8.0.1</FullProductName>
                </Branch>
                <Branch Name="8.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-8.0.0">FortiWeb 8.0.0</FullProductName>
                </Branch>
                <Branch Name="7.6.5" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.5">FortiWeb 7.6.5</FullProductName>
                </Branch>
                <Branch Name="7.6.4" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.4">FortiWeb 7.6.4</FullProductName>
                </Branch>
                <Branch Name="7.6.3" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.3">FortiWeb 7.6.3</FullProductName>
                </Branch>
                <Branch Name="7.6.2" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.2">FortiWeb 7.6.2</FullProductName>
                </Branch>
                <Branch Name="7.6.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.1">FortiWeb 7.6.1</FullProductName>
                </Branch>
                <Branch Name="7.6.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.0">FortiWeb 7.6.0</FullProductName>
                </Branch>
                <Branch Name="7.4.10" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.10">FortiWeb 7.4.10</FullProductName>
                </Branch>
                <Branch Name="7.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.9">FortiWeb 7.4.9</FullProductName>
                </Branch>
                <Branch Name="7.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.8">FortiWeb 7.4.8</FullProductName>
                </Branch>
                <Branch Name="7.4.7" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.7">FortiWeb 7.4.7</FullProductName>
                </Branch>
                <Branch Name="7.4.6" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.6">FortiWeb 7.4.6</FullProductName>
                </Branch>
                <Branch Name="7.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.5">FortiWeb 7.4.5</FullProductName>
                </Branch>
                <Branch Name="7.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.4">FortiWeb 7.4.4</FullProductName>
                </Branch>
                <Branch Name="7.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.3">FortiWeb 7.4.3</FullProductName>
                </Branch>
                <Branch Name="7.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.2">FortiWeb 7.4.2</FullProductName>
                </Branch>
                <Branch Name="7.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.1">FortiWeb 7.4.1</FullProductName>
                </Branch>
                <Branch Name="7.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.0">FortiWeb 7.4.0</FullProductName>
                </Branch>
                <Branch Name="7.2.11" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.11">FortiWeb 7.2.11</FullProductName>
                </Branch>
                <Branch Name="7.2.10" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.10">FortiWeb 7.2.10</FullProductName>
                </Branch>
                <Branch Name="7.2.9" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.9">FortiWeb 7.2.9</FullProductName>
                </Branch>
                <Branch Name="7.2.8" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.8">FortiWeb 7.2.8</FullProductName>
                </Branch>
                <Branch Name="7.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.7">FortiWeb 7.2.7</FullProductName>
                </Branch>
                <Branch Name="7.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.6">FortiWeb 7.2.6</FullProductName>
                </Branch>
                <Branch Name="7.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.5">FortiWeb 7.2.5</FullProductName>
                </Branch>
                <Branch Name="7.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.4">FortiWeb 7.2.4</FullProductName>
                </Branch>
                <Branch Name="7.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.3">FortiWeb 7.2.3</FullProductName>
                </Branch>
                <Branch Name="7.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.2">FortiWeb 7.2.2</FullProductName>
                </Branch>
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.1">FortiWeb 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.0">FortiWeb 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.11" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.11">FortiWeb 7.0.11</FullProductName>
                </Branch>
                <Branch Name="7.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.10">FortiWeb 7.0.10</FullProductName>
                </Branch>
                <Branch Name="7.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.9">FortiWeb 7.0.9</FullProductName>
                </Branch>
                <Branch Name="7.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.8">FortiWeb 7.0.8</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.7">FortiWeb 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.6">FortiWeb 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.5">FortiWeb 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.4">FortiWeb 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.3">FortiWeb 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.2">FortiWeb 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.1">FortiWeb 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.0">FortiWeb 7.0.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Capacity to forge authentication cookies</Title>
        <cvrf:CVE>CVE-2025-64447</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiWeb-8.0.1</ProductID>
                <ProductID>FortiWeb-8.0.0</ProductID>
                <ProductID>FortiWeb-7.6.5</ProductID>
                <ProductID>FortiWeb-7.6.4</ProductID>
                <ProductID>FortiWeb-7.6.3</ProductID>
                <ProductID>FortiWeb-7.6.2</ProductID>
                <ProductID>FortiWeb-7.6.1</ProductID>
                <ProductID>FortiWeb-7.6.0</ProductID>
                <ProductID>FortiWeb-7.4.10</ProductID>
                <ProductID>FortiWeb-7.4.9</ProductID>
                <ProductID>FortiWeb-7.4.8</ProductID>
                <ProductID>FortiWeb-7.4.7</ProductID>
                <ProductID>FortiWeb-7.4.6</ProductID>
                <ProductID>FortiWeb-7.4.5</ProductID>
                <ProductID>FortiWeb-7.4.4</ProductID>
                <ProductID>FortiWeb-7.4.3</ProductID>
                <ProductID>FortiWeb-7.4.2</ProductID>
                <ProductID>FortiWeb-7.4.1</ProductID>
                <ProductID>FortiWeb-7.4.0</ProductID>
                <ProductID>FortiWeb-7.2.11</ProductID>
                <ProductID>FortiWeb-7.2.10</ProductID>
                <ProductID>FortiWeb-7.2.9</ProductID>
                <ProductID>FortiWeb-7.2.8</ProductID>
                <ProductID>FortiWeb-7.2.7</ProductID>
                <ProductID>FortiWeb-7.2.6</ProductID>
                <ProductID>FortiWeb-7.2.5</ProductID>
                <ProductID>FortiWeb-7.2.4</ProductID>
                <ProductID>FortiWeb-7.2.3</ProductID>
                <ProductID>FortiWeb-7.2.2</ProductID>
                <ProductID>FortiWeb-7.2.1</ProductID>
                <ProductID>FortiWeb-7.2.0</ProductID>
                <ProductID>FortiWeb-7.0.11</ProductID>
                <ProductID>FortiWeb-7.0.10</ProductID>
                <ProductID>FortiWeb-7.0.9</ProductID>
                <ProductID>FortiWeb-7.0.8</ProductID>
                <ProductID>FortiWeb-7.0.7</ProductID>
                <ProductID>FortiWeb-7.0.6</ProductID>
                <ProductID>FortiWeb-7.0.5</ProductID>
                <ProductID>FortiWeb-7.0.4</ProductID>
                <ProductID>FortiWeb-7.0.3</ProductID>
                <ProductID>FortiWeb-7.0.2</ProductID>
                <ProductID>FortiWeb-7.0.1</ProductID>
                <ProductID>FortiWeb-7.0.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>7.1</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-25-945</URL>
                <Description>Capacity to forge authentication cookies</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>