Heap-based Buffer Overflow in Fortinet FortiOS Affects Multiple Versions
CVE-2025-24477

4MEDIUM

Key Information:

Vendor

Fortinet

Status
Vendor
CVE Published:
15 July 2025

What is CVE-2025-24477?

A heap-based buffer overflow vulnerability exists in Fortinet's FortiOS, impacting versions 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, and 7.2.4 through 7.2.11. This vulnerability could potentially allow attackers to escalate their privileges by employing a specially crafted CLI command. Organizations using affected FortiOS versions are urged to implement the necessary updates and security measures to mitigate the risk.

Affected Version(s)

FortiOS 7.6.0 <= 7.6.2

FortiOS 7.4.0 <= 7.4.7

FortiOS 7.2.4 <= 7.2.11

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-24477 : Heap-based Buffer Overflow in Fortinet FortiOS Affects Multiple Versions