CVE-2025-47294

A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the csfd daemon via a specially crafted request.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

History

04 Jun 2025, 15:37

Type Values Removed Values Added
CPE cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
First Time Fortinet
Fortinet fortios
References () https://fortiguard.fortinet.com/psirt/FG-IR-24-388 - () https://fortiguard.fortinet.com/psirt/FG-IR-24-388 - Vendor Advisory

28 May 2025, 15:01

Type Values Removed Values Added
Summary
  • (es) Un desbordamiento de enteros o un error en las versiones 7.2.0 a 7.2.7 y 7.0.0 a 7.0.14 de Fortinet FortiOS puede permitir que un atacante remoto no autenticado bloquee el daemon csfd a través de una solicitud especialmente manipulada.

28 May 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-28 08:15

Updated : 2025-06-04 15:37


NVD link : CVE-2025-47294

Mitre link : CVE-2025-47294

CVE.ORG link : CVE-2025-47294


JSON object : View

Products Affected

fortinet

  • fortios
CWE
CWE-190

Integer Overflow or Wraparound