Record summary

CVE-2025-22258 has a selected CVSS score of 5.7 (medium).

Description

A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.2 through 7.0.16, FortiSwitchManager 7.2.1 through 7.2.5 allows attackers to escalate their privilege via specially crafted http requests.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 17, 2025 · Source: CVE List

Affected products and versions

5
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List7.6.0 to ≤ 7.6.2affected
7.4.0 to ≤ 7.4.6affected
7.2.0 to ≤ 7.2.10affected
7.0.2 to ≤ 7.0.16affected

Default status: unaffected

CVE List1.5.0affected
1.4.0 to ≤ 1.4.2affected
1.3.0 to ≤ 1.3.1affected
1.2.0affected
1.1.0 to ≤ 1.1.2affected
1.0.0 to ≤ 1.0.3affected

Default status: unaffected

CVE List7.6.0 to ≤ 7.6.1affected
7.4.0 to ≤ 7.4.7affected

Default status: unaffected

CVE List1.5.0affected
1.4.0 to ≤ 1.4.2affected

Default status: unaffected

CVE List7.2.1 to ≤ 7.2.5affected

References

2