CVE-2025-64155
9.8Fortinet · FortiSIEM
An OS command injection vulnerability in Fortinet FortiSIEM allows unauthenticated attackers to execute arbitrary code or commands via crafted TCP requests.
Executive summary
A critical OS command injection vulnerability in Fortinet FortiSIEM allows for unauthenticated remote code execution via crafted TCP requests.
Vulnerability
This is an OS command injection flaw (CWE-78) that occurs due to improper neutralization of special elements in TCP requests. The vulnerability is exploitable by an unauthenticated attacker over the network.
Business impact
Successful exploitation allows an attacker to gain full control over the affected FortiSIEM instance, potentially leading to unauthorized access to sensitive security data and the ability to pivot into internal networks. The CVSS score of 9.8 reflects the high risk of total system compromise.
Remediation
Immediate Action: Upgrade to FortiSIEM version 7.5.0, 7.4.1, 7.3.5, 7.2.7, or 7.1.9, depending on your current release branch.
Proactive Monitoring: Monitor network traffic for anomalous TCP connections directed at the FortiSIEM infrastructure and inspect logs for unauthorized command execution patterns.
Compensating Controls: Implement strict network access control lists (ACLs) to restrict access to the FortiSIEM interface to authorized management subnets only.
Exploitation status
Public Exploit Available: Yes — multiple public proof-of-concept repositories are available on GitHub.
Analyst recommendation
Given the availability of public proof-of-concept code and the ease of exploitation, this vulnerability requires immediate patching. Administrators should verify their FortiSIEM version and apply the recommended vendor updates without delay.