Fortinet
Multiple Products
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb...
2025-11-15
Description
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
Remediation
FEDERAL DEADLINE: November 20, 2025 (6 days). Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. FEDERAL DEADLINE: November 20, 2025 (6 days). Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Update A relative path traversal vulnerability in Fortinet FortiWeb Multiple Products to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
CISA KEV Details
Deadline: November 20, 2025
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Executive Summary:
A high-severity vulnerability has been identified in the CycloneDX core module, which is responsible for parsing and validating Software Bill of Materials (SBOMs). An attacker could exploit this flaw by crafting a malicious SBOM file, which, when processed by a vulnerable application, could lead to arbitrary code execution. Successful exploitation could compromise systems integral to the software development lifecycle and supply chain security, potentially allowing an attacker to steal sensitive data or inject malicious code into software builds.
Vulnerability Details
CVE-ID: CVE-2025-64518
Affected Software: CycloneDX Multiple Products
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The vulnerability exists within the parsing utility of the CycloneDX core module. It stems from the insecure deserialization of untrusted data when processing a specially crafted SBOM file. An unauthenticated, remote attacker can create a malicious SBOM containing a crafted payload. When a vulnerable system or application ingests and parses this file, the payload is deserialized, leading to arbitrary code execution with the permissions of the application processing the SBOM.
Business Impact
This vulnerability is rated as High severity with a CVSS score of 7.5. Exploitation could have a significant business impact by compromising the integrity of the software supply chain. An attacker could gain control over critical systems such as build servers, artifact repositories, or security scanning tools that rely on CycloneDX for SBOM processing. Potential consequences include the theft of source code and intellectual property, injection of malware into the organization's software products, and disruption of development and deployment pipelines, leading to reputational damage and financial loss.
Remediation Plan
Immediate Action: Apply vendor-provided security updates to all affected CycloneDX implementations immediately. Prioritize systems that process SBOMs from external or untrusted sources. After patching, monitor for any signs of exploitation attempts and review historical access logs for indicators of compromise preceding the patch application.
Proactive Monitoring: Implement enhanced monitoring on systems utilizing the CycloneDX library. Look for anomalous process execution, unexpected network connections originating from applications that parse SBOMs, and review application logs for deserialization errors or warnings. Utilize Endpoint Detection and Response (EDR) solutions to detect suspicious behavior associated with the application's user account.
Compensating Controls: If immediate patching is not feasible, implement the following controls:
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of November 10, 2025, there are no known public proof-of-concept exploits or active exploitation campaigns targeting this vulnerability. However, due to the critical function of SBOMs in software supply chain security, the development of exploit code by threat actors is highly probable.
Analyst Recommendation
Given the high severity of this vulnerability and its strategic location within the software supply chain, we recommend immediate action. Organizations must prioritize applying the vendor's security patches to all systems using the affected CycloneDX products. Although this CVE is not currently on the CISA KEV list, its potential for widespread impact warrants urgent attention. Proactive monitoring for indicators of compromise should be implemented concurrently with patching efforts to ensure the integrity of development and security environments.