CVE-2025-25256: OS Command Injection
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSIEM version 7.3.0 through 7.3.1, 7.2.0 through 7.2.5, 7.1.0 through 7.1.7, 7.0.0 through 7.0.3 and before 6.7.9 allows an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25256?
CVE-2025-25256 has a high severity rating due to its potential for OS command injection by unauthenticated attackers.
How do I fix CVE-2025-25256?
To fix CVE-2025-25256, users should upgrade Fortinet FortiSIEM to the latest versions beyond 7.3.1, 7.2.5, 7.1.7, 7.0.3, or before 6.7.9.
Which versions of Fortinet FortiSIEM are affected by CVE-2025-25256?
CVE-2025-25256 affects Fortinet FortiSIEM versions 7.3.0 to 7.3.1, 7.2.0 to 7.2.5, 7.1.0 to 7.1.7, 7.0.0 to 7.0.3, and all versions prior to 6.7.9.
Can CVE-2025-25256 be exploited remotely?
Yes, CVE-2025-25256 can be exploited remotely by an unauthenticated attacker.
What kind of vulnerability is CVE-2025-25256 classified as?
CVE-2025-25256 is classified as an OS Command Injection vulnerability, specifically due to improper neutralization of special elements.