HomeSecurityFortinet administrators urged to update software to close vulnerabilities...

Fortinet administrators urged to update software to close FortiCloud SSO vulnerabilities

Administrators using FortiCloud SSO (single sign-on) to authenticate access to Fortinet are urged to upgrade the software running on some of the company’s gateway products as soon as possible, or risk their networks being compromised. “Fortinet appliance users should, for now, disable SSO until they can update their appliances,” advises Johannes Ullrich, research dean at the SANS Institute.

See also: Fortinet, Ivanti and SAP patch critical vulnerabilities

FortiCloud SSO

The vulnerabilities, CVE-2025-59718 and CVE-2025-59719 , are cryptographic signature vulnerabilities in the FortiOS operating system running on Fortinet devices, as well as FortiWeb, FortiProxy , and FortiSwitchManager products . They allow an unauthenticated attacker to bypass FortiCloud SSO login authentication via a crafted SAML (security assertion markup language) message, if this feature is enabled on the device.

In an advisory, Fortinet notes that the FortiCloud SSO login feature is not enabled by default in the factory settings. However, when an administrator enrolls the device with FortiCare product support from the device GUI, single sign-on is enabled unless they disable the “Allow administrator login using FortiCloud SSO” setting on the enrollment page.

Single sign-on allows users to enter one password to access multiple applications or services, and in this case allows an administrator to oversee multiple Fortinet devices. Fortinet uses SAML as the underlying protocol, he explains, noting that it is a complex protocol, and many implementations of it have had problems in the past.

See also: Fortinet: 'Silent' patch for second zero-day vulnerability

Fortinet administrators urged to update software to close FortiCloud SSO vulnerabilities

Just yesterday, the same day that Fortinet updated its systems, Ruby released an update for its SAML library. It added that SAML implementations often suffer from issues due to the complexities of XML parsing and ambiguities in interpreting the result. To avoid being affected by this flaw, Fortinet says administrators should disable the FortiCloud SSO login feature (if enabled) until they upgrade to an unaffected version.

To disable FortiCloud login, go to System -> Settings, and then change “Allow admin login using FortiCloud SSO” to Disabled. Alternatively, administrators can use the command line interface and enter: config system global set admin-forticloud-sso-login disable end. Affected applications should then be updated to the latest versions, and SSO re-enabled.

Robert Beggs, head of incident response at Canadian company DigitalDefence, said that fortunately the vulnerability was discovered by FortiGuard's internal team. The fact that a pair of vulnerabilities affect a number of offerings from one manufacturer shows the downside of having a common code base for their products, Beggs added.

See also: Vulnerability in FortiPAM and FortiSwitch Manager bypasses verification process

Fortinet administrators urged to update software to close FortiCloud SSO vulnerabilities

While on the one hand, it allows the vendor to quickly scale the number and functionality of products and ensure integrated functionality, on the other hand, the code base becomes a single point of failure. These FortiGuard issues show both sides of the coin.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS