CVE-2025-24477

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its privileges via a specia

Severity
Medium 4
CVSS 3.1
Exploited
Not listed
EPSS
0.002
11.5th percentile
Discovered by
Not disclosed
Published
Jul 15, 2025
Assigned by fortinet

Description

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its privileges via a specially crafted CLI command

Weakness: CWE-122

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiOS

Vendor remediation

Upgrade to FortiOS version 7.6.3 or above Upgrade to FortiOS version 7.4.8 or above Upgrade to FortiOS version 7.2.13 or above