CVE-2025-25248

MEDIUM

FortiOS, FortiProxy, FortiPAM - Authenticated Denial of Service via SSL-VPN RDP and VNC Bookmarks

Title source: llm
STIX 2.1

Description

An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions and FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions SSL-VPN RDP and VNC bookmarks may allow an authenticated user to affect the device SSL-VPN availability via crafted requests.

Scores

CVSS v3 5.3
EPSS 0.0042
EPSS Percentile 33.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-190
Status published
Products (20)
Fortinet/FortiOS 6.4.0 - 6.4.16
fortinet/fortios 6.4.0 - 7.2.11
Fortinet/FortiOS 7.0.0 - 7.0.17
Fortinet/FortiOS 7.2.0 - 7.2.10
Fortinet/FortiOS 7.4.0 - 7.4.7
Fortinet/FortiOS 7.6.0 - 7.6.2
fortinet/fortipam 1.5.0
Fortinet/FortiPAM 1.0.0 - 1.0.3
fortinet/fortipam 1.0.0 - 1.4.3
Fortinet/FortiPAM 1.1.0 - 1.1.2
... and 10 more
Published Aug 12, 2025
Tracked Since Feb 18, 2026