CVE-2025-64155

Source
https://cve.org/CVERecord?id=CVE-2025-64155
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64155.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-64155
Withdrawn
2026-05-04T08:48:02.706695Z
Published
2026-01-13T17:15:58.440Z
Modified
2026-05-04T08:48:02.706695Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "6.7.0"
            },
            {
                "fixed": "7.1.9"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.2.0"
            },
            {
                "fixed": "7.2.7"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.3.0"
            },
            {
                "fixed": "7.3.5"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "7.4.0"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64155.json"