fortiguard.fortinet.com
https://fortiguard.fortinet.com/psirt/FG-IR-24-546 CVE-2025-22258
MEDIUM
Record summary
CVE-2025-22258 has a selected CVSS score of 5.7 (medium).
Description
A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.2 through 7.0.16, FortiSwitchManager 7.2.1 through 7.2.5 allows attackers to escalate their privilege via specially crafted http requests.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 17, 2025 · Source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
FortiOSBrowse Fortinet / FortiOSDefault status: unaffected | CVE List | 7.6.0 to ≤ 7.6.2 | affected |
| 7.4.0 to ≤ 7.4.6 | affected | ||
| 7.2.0 to ≤ 7.2.10 | affected | ||
| 7.0.2 to ≤ 7.0.16 | affected | ||
FortiPAMBrowse Fortinet / FortiPAMDefault status: unaffected | CVE List | 1.5.0 | affected |
| 1.4.0 to ≤ 1.4.2 | affected | ||
| 1.3.0 to ≤ 1.3.1 | affected | ||
| 1.2.0 | affected | ||
| 1.1.0 to ≤ 1.1.2 | affected | ||
| 1.0.0 to ≤ 1.0.3 | affected | ||
FortiProxyBrowse Fortinet / FortiProxyDefault status: unaffected | CVE List | 7.6.0 to ≤ 7.6.1 | affected |
| 7.4.0 to ≤ 7.4.7 | affected | ||
FortiSRABrowse Fortinet / FortiSRADefault status: unaffected | CVE List | 1.5.0 | affected |
| 1.4.0 to ≤ 1.4.2 | affected | ||
FortiSwitchManagerBrowse Fortinet / FortiSwitchManagerDefault status: unaffected | CVE List | 7.2.1 to ≤ 7.2.5 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-22258