A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiVoice versions 7.2.0, 7.0.0 through 7.0.6, 6.4.0 through 6.4.10, FortiRecorder versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.5, 6.4.0 through 6.4.5, FortiMail versions 7.6.0 through 7.6.2, 7.4.0 through 7.4.4, 7.2.0 through 7.2.7, 7.0.0 through 7.0.8, FortiNDR versions 7.6.0, 7.4.0 through 7.4.7, 7.2.0 through 7.2.4, 7.0.0 through 7.0.6, FortiCamera versions 2.1.0 through 2.1.3, 2.0 all versions, 1.1 all versions, allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-25-254 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
History
16 May 2025, 19:41
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:fortinet:fortivoice:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortindr:7.6.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortindr:1.1.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortindr:*:*:*:*:*:*:*:* cpe:2.3:h:fortinet:forticamera:-:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortindr:1.3.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortindr:7.1.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:forticamera_firmware:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortindr:1.2.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortirecorder:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortivoice:7.2.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortindr:1.5.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortindr:7.1.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortindr:1.4.0:*:*:*:*:*:*:* |
|
References | () https://fortiguard.fortinet.com/psirt/FG-IR-25-254 - Vendor Advisory | |
CWE | CWE-787 | |
First Time |
Fortinet fortindr
Fortinet forticamera Fortinet fortimail Fortinet fortirecorder Fortinet Fortinet forticamera Firmware Fortinet fortivoice |
15 May 2025, 01:00
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
13 May 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-13 15:15
Updated : 2025-05-16 19:41
NVD link : CVE-2025-32756
Mitre link : CVE-2025-32756
CVE.ORG link : CVE-2025-32756
JSON object : View
Products Affected
fortinet
- forticamera_firmware
- fortimail
- fortindr
- forticamera
- fortivoice
- fortirecorder