CVE-2025-47294: Denial of Service in Security Fabric Root
A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the csfd daemon via a specially crafted request.
Other sources
An integer overflow or wraparound vulnerability [CWE-190] in FortiOS Security Fabric may allow a remote unauthenticated attacker to crash the csfd daemon via a specially crafted request.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47294?
CVE-2025-47294 is considered a critical vulnerability as it allows remote unauthenticated attackers to crash the csfd daemon.
How do I fix CVE-2025-47294?
To mitigate CVE-2025-47294, upgrade FortiOS to version 7.2.8 or later, or to version 7.0.15 or later.
What versions of FortiOS are affected by CVE-2025-47294?
CVE-2025-47294 affects FortiOS versions 7.2.0 to 7.2.7 and 7.0.0 to 7.0.14, as well as version 6.4.
Is there a workaround for CVE-2025-47294?
There is no known workaround for CVE-2025-47294; the recommended action is to update to the fixed versions.
What impact does CVE-2025-47294 have on FortiOS devices?
CVE-2025-47294 allows attackers to crash the csfd daemon, potentially disrupting services on affected FortiOS devices.