CVE-2025-24477
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its privileges via a specia
Severity
Medium 4
CVSS 3.1
Exploited
Not listed
EPSS
0.002
11.3th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jul 15, 2025
Assigned by fortinet
Description
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its privileges via a specially crafted CLI command
Weakness: CWE-122
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiOS
Credit
Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security team.
Vendor remediation
Upgrade to FortiOS version 7.6.3 or above Upgrade to FortiOS version 7.4.8 or above Upgrade to FortiOS version 7.2.13 or above