CVE-2025-53847
⚪ Do wiadomości
Brak uwierzytelnienia w FortiOS pozwala na wykonanie nieautoryzowanego kodu.
CVSS
6.5
EPSS
0.3%
Exploit
none
Vendor
fortinet
Opis źródłowy (NVD)
A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or commands via specially crafted packets.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-04-14 16:16:30 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 09:10:00 UTC |
Referencje
- https://fortiguard.fortinet.com/psirt/FG-IR-26-125 ([email protected]) [Vendor Advisory]
- https://cert-portal.siemens.com/productcert/html/ssa-975644.html (0b142b55-0307-4c5a-b3c9-f314f3fb7c5e)