CVE-2025-47295: Buffer over-read in FGFM
A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially crafted request, under rare conditions that are outside of the attacker's control.
Other sources
A buffer over-read vulnerability [CWE-126] in FortiOS may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially crafted request, under rare conditions that are outside of the attacker's control.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47295?
CVE-2025-47295 is a critical vulnerability that can allow a remote unauthenticated attacker to crash the FGFM daemon.
How do I fix CVE-2025-47295?
To fix CVE-2025-47295, upgrade FortiOS to version 7.4.4 or higher, 7.2.8 or higher, or 7.0.15 or higher depending on your current version.
Which versions of FortiOS are affected by CVE-2025-47295?
CVE-2025-47295 affects FortiOS versions 7.4.0 to 7.4.3, 7.2.0 to 7.2.7, and 7.0.0 to 7.0.14.
Can CVE-2025-47295 be exploited remotely?
Yes, CVE-2025-47295 can be exploited remotely by an unauthenticated attacker.
What is a buffer over-read vulnerability like CVE-2025-47295?
A buffer over-read vulnerability occurs when a program reads more data from a buffer than it is supposed to, potentially leading to information leakage or crashes.