cert-portal.siemens.com
https://cert-portal.siemens.com/productcert/html/ssa-864900.html CVE-2025-57740
MEDIUM
Record summary
CVE-2025-57740 has a selected CVSS score of 6.7 (medium).
Description
An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions RDP bookmark connection may allow an authenticated user to execute unauthorized code via crafted requests.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 16, 2025 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
FortiOSBrowse Fortinet / FortiOSDefault status: unaffected | CVE List | 7.6.0 to ≤ 7.6.2 | affected |
| 7.4.0 to ≤ 7.4.7 | affected | ||
| 7.2.0 to ≤ 7.2.10 | affected | ||
| 7.0.0 to ≤ 7.0.18 | affected | ||
| 6.4.0 to ≤ 6.4.16 | affected | ||
FortiPAMBrowse Fortinet / FortiPAMDefault status: unaffected | CVE List | 1.5.0 | affected |
| 1.4.0 to ≤ 1.4.2 | affected | ||
| 1.3.0 to ≤ 1.3.1 | affected | ||
| 1.2.0 | affected | ||
| 1.1.0 to ≤ 1.1.2 | affected | ||
| 1.0.0 to ≤ 1.0.3 | affected | ||
FortiProxyBrowse Fortinet / FortiProxyDefault status: unaffected | CVE List | 7.6.0 to ≤ 7.6.2 | affected |
| 7.4.0 to ≤ 7.4.3 | affected | ||
| 7.2.0 to ≤ 7.2.15 | affected | ||
| 7.0.0 to ≤ 7.0.22 | affected | ||
RUGGEDCOM APE1808Browse Siemens / RUGGEDCOM APE1808Default status: unknown | CVE List | Before * | affected |
References
3fortiguard.fortinet.com
https://fortiguard.fortinet.com/psirt/FG-IR-25-756 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-57740