CVE-2025-53844
🟡 Monitoruj
Przepełnienie bufora w FortiOS umożliwia zdalne wykonanie nieautoryzowanego kodu.
CVSS
8.8
EPSS
0.6%
Exploit
none
Vendor
fortinet
Opis źródłowy (NVD)
A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.6% |
| Opublikowano (NVD) | 2026-05-12 18:16:35 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 09:10:00 UTC |
Referencje
- https://fortiguard.fortinet.com/psirt/FG-IR-26-123 ([email protected]) [Vendor Advisory]
- https://cert-portal.siemens.com/productcert/html/ssa-864900.html (0b142b55-0307-4c5a-b3c9-f314f3fb7c5e)