CVE-2023-25603: Fortinet FortiADC

Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information via crafted web requests.

Affected products

  • Fortinet FortiADC: version 7.1.0 only; version 7.1.1 only
  • Fortinet Fortiddos-F: from 6.3.0, up to and including 6.3.4; version 6.4.0 only; version 6.4.1 only

Published 2023-11-14. Last modified 2026-06-17.