CVE-2025-47855: Infoleak
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47855?
CVE-2025-47855 is classified as a high severity vulnerability due to its potential to expose sensitive device configurations.
How do I fix CVE-2025-47855?
To fix CVE-2025-47855, update Fortinet FortiFone to the latest version that addresses the vulnerability.
What versions are impacted by CVE-2025-47855?
CVE-2025-47855 affects Fortinet FortiFone versions 7.0.0 through 7.0.1 and 3.0.13 through 3.0.23.
What kind of attacks can exploit CVE-2025-47855?
CVE-2025-47855 can be exploited by unauthenticated attackers using crafted HTTP or HTTPS requests to access device configurations.
What is the nature of the vulnerability described in CVE-2025-47855?
CVE-2025-47855 is an exposure of sensitive information vulnerability, allowing unauthorized access to sensitive device configuration data.