CVE-2025-57740

HIGH

Fortinet Fortiproxy < 7.4.4 - Heap Buffer Overflow

Title source: rule
STIX 2.1

Description

An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions RDP bookmark connection may allow an authenticated user to execute unauthorized code via crafted requests.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0008
EPSS Percentile 23.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-122
Status published
Products (4)
fortinet/fortios 6.4.0 - 7.2.11
fortinet/fortipam 1.5.0
fortinet/fortipam 1.0.0 - 1.4.3
fortinet/fortiproxy 7.0.0 - 7.4.4
Published Oct 14, 2025
Tracked Since Feb 18, 2026