CVE-2025-25248: Integer Overflow on SSL-VPN bookmarks
An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions and FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions SSL-VPN RDP and VNC bookmarks may allow an authenticated user to affect the device SSL-VPN availability via crafted requests.
Other sources
An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS, FortiPAM and FortiProxy SSL-VPN RDP and VNC bookmarks may allow an authenticated user to affect the device SSL-VPN availability via crafted requests.
— FortiGuard
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.2.11 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.8 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.3 - Upgrade
Upgrade
FortiPAMto a version that resolves this vulnerability.Fixed in 1.4.3 - Upgrade
Upgrade
FortiPAMto a version that resolves this vulnerability.Fixed in 1.5.1 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.4.4 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.6.3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25248?
CVE-2025-25248 has been classified as a high-severity vulnerability that can lead to potential exploitation via integer overflow.
How do I fix CVE-2025-25248?
To remediate CVE-2025-25248, upgrade to FortiOS version 7.6.3 or above, or FortiProxy version 7.6.3 or above, depending on your affected product.
What versions of FortiOS are affected by CVE-2025-25248?
CVE-2025-25248 affects FortiOS versions 7.6.2 and below, 7.4.7 and below, 7.2.10 and below, along with all versions of 7.2, 6.4, and earlier.
What products are impacted by CVE-2025-25248?
CVE-2025-25248 impacts FortiOS, FortiProxy, and FortiPAM products depending on their specified versions.
Is there a workaround for CVE-2025-25248?
There are no available workarounds for CVE-2025-25248; updating to the fixed versions is the recommended action.