CVE-2025-47294

A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the csfd daemon via a specially cr

Severity
Medium 4.8
CVSS 3.1
Exploited
Not listed
EPSS
0.007
49.4th percentile
Discovered by
Not disclosed
Published
May 28, 2025
Assigned by fortinet

Description

A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the csfd daemon via a specially crafted request.

Weakness: CWE-190

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiOS

Vendor remediation

Please upgrade to FortiOS version 7.2.8 or above Please upgrade to FortiOS version 7.0.15 or above