PT-2025-23070 · Fortinet · Fortios

Published

2025-05-13

·

Updated

2025-06-04

·

CVE-2025-47294

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Fortinet FortiOS versions 7.2.0 through 7.2.7 Fortinet FortiOS versions 7.0.0 through 7.0.14
Description The issue is related to an integer overflow or wraparound that may allow a remote unauthenticated attacker to crash the csfd daemon via a specially crafted request.
Recommendations For Fortinet FortiOS versions 7.2.0 through 7.2.7, update to a version that fixes the integer overflow issue to prevent the csfd daemon from being crashed by a specially crafted request. For Fortinet FortiOS versions 7.0.0 through 7.0.14, update to a version that fixes the integer overflow issue to prevent the csfd daemon from being crashed by a specially crafted request.

Fix

DoS

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-09057
CVE-2025-47294

Affected Products

Fortios