IM
IronMonkey Threat Research

CVE-2025-25248 MEDIUM

Published: 2025-08-12 | Last Modified: 2026-06-09 | Status: Modified

Description

An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions and FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions SSL-VPN RDP and VNC bookmarks may allow an authenticated user to affect the device SSL-VPN availability via crafted requests.

Additional Descriptions (1)

Una vulnerabilidad de desbordamiento de entero o envolvente [CWE-190] en FortiOS versión 7.6.2 y anteriores, versión 7.4.7 y anteriores, versión 7.2.10 y anteriores, 7.2 todas las versiones, 6.4 todas las versiones, FortiProxy versión 7.6.2 y anteriores, versión 7.4.3 y anteriores, 7.2 todas las versiones, 7.0 todas las versiones, 2.0 todas las versiones y FortiPAM versión 1.5.0, versión 1.4.2 y anteriores, 1.3 todas las versiones, 1.2 todas las versiones, 1.1 todas las versiones, 1.0 todas las versiones Los marcadores SSL-VPN RDP y VNC pueden permitir que un usuario autenticado afecte la disponibilidad de SSL-VPN del dispositivo a través de solicitudes manipuladas.

CVSS Metrics

Base Score: 6.5 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 2.8

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-190

Affected Products

Vendor Product Version Update Type
fortinet fortios * <built-in method update of dict object at 0x763e8fe459c0> Operating System
fortinet fortios * <built-in method update of dict object at 0x763ef7b85480> Operating System
fortinet fortios * <built-in method update of dict object at 0x763ef7c98280> Operating System
fortinet fortipam * <built-in method update of dict object at 0x763e8fe454c0> Operating System
fortinet fortipam 1.5.0 <built-in method update of dict object at 0x763e8fe47500> Operating System
fortinet fortiproxy * <built-in method update of dict object at 0x763e8fe47ac0> Application
fortinet fortiproxy * <built-in method update of dict object at 0x763e8fe47640> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:fortinet:fortipam:1.5.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
Notification
Message here