peter bassill · operator
$ cve CVE-2025-64155 JSON

CVE-2025-64155

9.8
CRITICAL · CVSS 3.1 · EPSS 42.8% (pctl 99)

Patch early

EPSS 42.8% — above the 10% action threshold.

Description

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS42.81% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2026-01-13
Last modified2026-06-17

Affected (1)

VendorProduct
fortinetfortisiem

References

→ the Explorer  ·  watch your stack  ·  NVD