CVE-2025-22258

Severity
7.2HIGH
EPSS
0.1%
top 76.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14

Description

A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.2 through 7.0.16, FortiSwitchManager 7.2.1 through 7.2.5 allows attackers to escalate their privilege via specially crafted http requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:HExploitability: 1.2 | Impact: 5.2

Affected Packages10 packages

NVDfortinet/fortios7.0.27.0.17+3
NVDfortinet/fortipam1.0.01.4.3+1
NVDfortinet/fortisra1.4.01.4.3+1
NVDfortinet/fortiproxy7.4.07.4.8+1
NVDfortinet/fortiswitchmanager7.2.17.2.6

🔴Vulnerability Details

2
CVEList
CVE-2025-22258: A heap-based buffer overflow in Fortinet FortiSRA 12025-10-14
GHSA
GHSA-5hxp-wcvm-357w: A heap-based buffer overflow in Fortinet FortiSRA 12025-10-14

📋Vendor Advisories

1
Fortinet
Heap buffer overflow in websocket2025-10-14
CVE-2025-22258 (HIGH CVSS 7.2) | A heap-based buffer overflow in For | cvebase.io