---
cve: "CVE-2025-54821"
severity: "LOW"
cvss: 1.8
epss: "15%"
vendor: "Fortinet"
kev: false
exploited: false
published: "2025-11-18 17:16:03"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-14T05:41:09+02:00"
---

# CVE-2025-54821

> 1.8 LOW

## Beschreibung

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSASE 25.2.91 may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:R
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Hoch | good |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-269** — Improper Privilege Management
  The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

## Angriffsmuster (CAPEC)

- [CAPEC-58 — Restful Privilege Elevation](https://capec.mitre.org/data/definitions/58.html) _(Severity: High)_
- [CAPEC-122 — Privilege Abuse](https://capec.mitre.org/data/definitions/122.html) _(Severity: Medium)_
- [CAPEC-233 — Privilege Escalation](https://capec.mitre.org/data/definitions/233.html)

## ATT&CK-Techniken

- [T1548 — Abuse Elevation Control Mechanism](https://attack.mitre.org/techniques/T1548/)

## Referenzen

- <https://fortiguard.fortinet.com/psirt/FG-IR-25-545>
- <https://cert-portal.siemens.com/productcert/html/ssa-864900.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-54821) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
