CVE-2025-25249: Fortinet Multiple Products
Fortinet FortiOS、FortiSwitchManager、FortiSASEには、特別に作られたパケットを使用して、不正なコードやコマンドを実行できるヒープベースのバッファオーバーフロー脆弱性が含まれています。
CISA (English)
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
- ベンダー
- Fortinet
- 製品
- Multiple Products
- 脆弱性
- Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- 追加日
- 2026/09/09
- CISA対応期限(米国連邦機関向け)
- 2026/09/12
- ランサムウェア攻撃での利用
- 不明
- 弱点(CWE)
- CWE-122, CWE-787
参考情報
当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。
最終更新: · カタログのバージョン 2026.10.02