CVE-2025-25256: OS Command Injection
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, FortiSIEM 7.0.0 through 7.0.3, FortiSIEM 6.7.0 through 6.7.9, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions, FortiSIEM 6.4 all versions, FortiSIEM 6.3 all versions, FortiSIEM 6.2 all versions, FortiSIEM 6.1 all versions, FortiSIEM 5.4 all versions, FortiSIEM 5.3 all versions, FortiSIEM 5.2 all versions, FortiSIEM 5.1 all versions, FortiSIEM 5.0 all versions, FortiSIEM 4.10 all versions, FortiSIEM 4.9 all versions, FortiSIEM 4.7 all versions allows an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiSIEMto a version that resolves this vulnerability.Fixed in 6.7.10 - Upgrade
Upgrade
Fortinet FortiSIEMto a version that resolves this vulnerability.Fixed in 7.0.4 - Upgrade
Upgrade
Fortinet FortiSIEMto a version that resolves this vulnerability.Fixed in 7.1.8 - Upgrade
Upgrade
Fortinet FortiSIEMto a version that resolves this vulnerability.Fixed in 7.2.6 - Upgrade
Upgrade
Fortinet FortiSIEMto a version that resolves this vulnerability.Fixed in 7.3.2 - Upgrade
Upgrade
Fortinet FortiSIEMto a version that resolves this vulnerability.Fixed in 7.4.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25256?
CVE-2025-25256 has a high severity rating due to its potential for OS command injection by unauthenticated attackers.
How do I fix CVE-2025-25256?
To fix CVE-2025-25256, users should upgrade Fortinet FortiSIEM to the latest versions beyond 7.3.1, 7.2.5, 7.1.7, 7.0.3, or before 6.7.9.
Which versions of Fortinet FortiSIEM are affected by CVE-2025-25256?
CVE-2025-25256 affects Fortinet FortiSIEM versions 7.3.0 to 7.3.1, 7.2.0 to 7.2.5, 7.1.0 to 7.1.7, 7.0.0 to 7.0.3, and all versions prior to 6.7.9.
Can CVE-2025-25256 be exploited remotely?
Yes, CVE-2025-25256 can be exploited remotely by an unauthenticated attacker.
What kind of vulnerability is CVE-2025-25256 classified as?
CVE-2025-25256 is classified as an OS Command Injection vulnerability, specifically due to improper neutralization of special elements.