4.3
CVE-2025-43892
- EPSS 0.34%
- Veröffentlicht 14.07.2026 15:19:51
- Zuletzt bearbeitet 29.09.2026 14:10:00
- Erkennungen
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ FortiProxy Version >= 7.2.0 <= 7.2.15
Fortinet ≫ FortiProxy Version >= 7.4.0 <= 7.4.13
Fortinet ≫ FortiProxy Version >= 7.6.0 <= 7.6.5
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.264 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Fortinet | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-126 Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
https://cert-portal.siemens.com/productcert/html/ssa-864900.html
https://fortiguard.fortinet.com/psirt/#5944