CVE-2025-64155: OS Command Injection
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64155?
CVE-2025-64155 is rated as critical due to its potential for unauthorized command execution.
How do I fix CVE-2025-64155?
To fix CVE-2025-64155, users should update to the patched versions of FortiSIEM specified by Fortinet.
What versions of Fortinet FortiSIEM are affected by CVE-2025-64155?
CVE-2025-64155 affects FortiSIEM versions 6.7.0 to 6.7.10, 7.0.0 to 7.0.4, 7.1.0 to 7.1.8, 7.3.0 to 7.3.4, and 7.4.0.
What type of vulnerability is CVE-2025-64155?
CVE-2025-64155 is an os command injection vulnerability, allowing attackers to execute arbitrary commands.
Who reported CVE-2025-64155?
CVE-2025-64155 was reported by Fortinet through its PSIRT team following security assessments.