Database/Control plane, storage & DevOps
Fortinet FortiOS and FortiSwitchManager: heap overflow in packet handling gives unauthenticated code execution
Impact
A heap-based buffer overflow reachable from specially crafted packets lets an unauthenticated attacker execute code or commands on the appliance. Where a FortiGate is the edge or segmentation firewall in front of a GPU fleet, that is control of the device that enforces which management VLANs, tenant networks and storage segments can talk to each other, plus whatever VPN and admin credentials the box terminates. FortiSwitchManager is worse in one respect: it fans out to the switching layer, so one compromised manager reaches the datacenter switch estate. CISA lists this as exploited in the wild, and Siemens ships the affected FortiOS inside RUGGEDCOM APE1808, so the same fix applies there through the Siemens advisory.
Who can reach it
Anyone who can send packets to an affected FortiOS or FortiSwitchManager interface. No authentication required. Exposure depends on which interfaces accept traffic - internet-facing VPN and admin interfaces are the worst case, but a management VLAN is enough.
What to do
Upgrade to a fixed build per Fortinet FG-IR-25-084 (6.4.x is listed as affected with no fixed branch given in this record - treat those units as end-of-support and plan replacement or isolation). This is an appliance image upgrade and reboot, not a package update: schedule per HA member and fail over between them, and expect sessions to drop. Until the window, restrict which networks can reach the appliance's listening interfaces. Because the flaw is already exploited, review the device for signs of compromise before and after the upgrade rather than treating the upgrade as the whole remediation.
References
Related entries
- Fortinet FortiWeb: Unauthenticated SQL injectionCVE-2025-25257 · Fortinet FortiWebCritical
- GitLab (ruby-saml): ReXML/Nokogiri parser differentialCVE-2025-25291 · GitLab (ruby-saml)Critical
- HPE StoreOnce: unauthenticated command injection allows remote code execution on the backup applianceCVE-2025-37089 · HPE StoreOnce (command injection RCE)Critical
- HPE StoreOnce (server-side request forgery): SSRF from the backup appliance, letting an unauthenticated attacker pivotCVE-2025-37090 · HPE StoreOnce (server-side request forgery)Critical
- HPE StoreOnce (authentication bypass): Unauthenticated attacker bypasses authentication on StoreOnce entirely, gainingCVE-2025-37093 · HPE StoreOnce (authentication bypass)Critical
- HPE StoreOnce (directory traversal information disclosure): Unauthenticated directory traversal disclosing filesCVE-2025-37095 · HPE StoreOnce (directory traversal information disclosure)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.