A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.2 through 7.0.16, FortiSwitchManager 7.2.1 through 7.2.5 allows attackers to escalate their privilege via specially crafted http requests.
                
            References
                    | Link | Resource | 
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-546 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
Configuration 3 (hide)
| 
 | 
Configuration 4 (hide)
| 
 | 
Configuration 5 (hide)
| 
 | 
History
                    15 Oct 2025, 17:34
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:fortinet:fortisra:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisra:1.5.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:1.5.0:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiswitchmanager:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | |
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-24-546 - Vendor Advisory | |
| First Time | Fortinet fortipam Fortinet Fortinet fortisra Fortinet fortiproxy Fortinet fortios Fortinet fortiswitchmanager | 
14 Oct 2025, 16:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-10-14 16:15
Updated : 2025-10-15 17:34
NVD link : CVE-2025-22258
Mitre link : CVE-2025-22258
CVE.ORG link : CVE-2025-22258
JSON object : View
Products Affected
                fortinet
- fortisra
- fortipam
- fortios
- fortiswitchmanager
- fortiproxy
CWE
                
                    
                        
                        CWE-122
                        
            Heap-based Buffer Overflow
