CVE-2025-43892

MEDIUM

Fortinet FortiOS - Buffer Over-read

Title source: rule
STIX 2.1

Description

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.

References (1)

Core 1

Scores

CVSS v3 4.3
EPSS 0.0032
EPSS Percentile 24.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-126
Status published
Products (5)
Fortinet/FortiOS 7.0.0 - 7.0.19
Fortinet/FortiOS 7.2.0 - 7.2.13
fortinet/fortios 7.2.0 - 7.2.13
Fortinet/FortiOS 7.4.0 - 7.4.3
fortinet/fortiproxy 7.2.0 - 7.2.15
Published Jul 14, 2026
Tracked Since Jul 14, 2026