CVE-2025-24477
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its privileges via a specia
Exploited
Not listed
EPSS
0.002
9.9th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jul 15, 2025
Assigned by fortinet
Description
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its privileges via a specially crafted CLI command
Weakness: CWE-122
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS Check your version | Firewall / NGFW | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiOS
Credit
Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security team.
Vendor remediation
Upgrade to FortiOS version 7.6.3 or above Upgrade to FortiOS version 7.4.8 or above Upgrade to FortiOS version 7.2.13 or above