CVE-2025-32756 Fortinet FortiNDR: Stack-based Buffer Overflow
9.6 KEV Explotada activamente según la CISA
Análisis en rafaelpfister.ch
Descripción del fabricante (en inglés)
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie. Datos de referencia
- Fabricante
- Fortinet
- Productos afectados
- FortiNDR
- FortiCamera
- FortiRecorder
- FortiVoice
- FortiMail
- CVSS 3.1
- 9.6 (CRITICAL)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:C- Tipo de debilidad
- CWE-121: Stack-based Buffer Overflow
- Publicada
- 13 de mayo de 2025
- En el catálogo KEV desde
- 14 de mayo de 2025
- Plazo agencias federales de EE. UU.
- 4 de junio de 2025