CVE-2025-32756 Fortinet FortiNDR: Stack-based Buffer Overflow
9.6 KEV Activement exploitée selon la CISA
Analyse sur rafaelpfister.ch
Description de l'éditeur (en anglais)
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie. Données de référence
- Éditeur
- Fortinet
- Produits concernés
- FortiNDR
- FortiCamera
- FortiRecorder
- FortiVoice
- FortiMail
- CVSS 3.1
- 9.6 (CRITICAL)
- Vecteur
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:C- Type de faiblesse
- CWE-121: Stack-based Buffer Overflow
- Publiée
- 13 mai 2025
- Dans le catalogue KEV depuis
- 14 mai 2025
- Échéance administrations fédérales US
- 4 juin 2025