First published: Tue May 13 2025(Updated: )
A buffer over-read vulnerability [CWE-126] in FortiOS may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially crafted request, under rare conditions that are outside of the attacker's control.
Affected Software | Affected Version | How to fix |
---|---|---|
FortiOS | >=7.4.0<=7.4.3 | |
FortiOS | >=7.2.0<=7.2.7 | |
FortiOS | >=7.0.0<=7.0.14 | |
FortiOS | >=6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-47295 is a critical vulnerability that can allow a remote unauthenticated attacker to crash the FGFM daemon.
To fix CVE-2025-47295, upgrade FortiOS to version 7.4.4 or higher, 7.2.8 or higher, or 7.0.15 or higher depending on your current version.
CVE-2025-47295 affects FortiOS versions 7.4.0 to 7.4.3, 7.2.0 to 7.2.7, and 7.0.0 to 7.0.14.
Yes, CVE-2025-47295 can be exploited remotely by an unauthenticated attacker.
A buffer over-read vulnerability occurs when a program reads more data from a buffer than it is supposed to, potentially leading to information leakage or crashes.