GPU VulnDB

Database/Control plane, storage & DevOps

Fortinet FortiOS and FortiSwitchManager: heap overflow in packet handling gives unauthenticated code execution

CVSS 9.8CVE-2025-25249Control plane, storage & DevOpsKnown exploitedcurated

Impact

A heap-based buffer overflow reachable from specially crafted packets lets an unauthenticated attacker execute code or commands on the appliance. Where a FortiGate is the edge or segmentation firewall in front of a GPU fleet, that is control of the device that enforces which management VLANs, tenant networks and storage segments can talk to each other, plus whatever VPN and admin credentials the box terminates. FortiSwitchManager is worse in one respect: it fans out to the switching layer, so one compromised manager reaches the datacenter switch estate. CISA lists this as exploited in the wild, and Siemens ships the affected FortiOS inside RUGGEDCOM APE1808, so the same fix applies there through the Siemens advisory.

Who can reach it

Anyone who can send packets to an affected FortiOS or FortiSwitchManager interface. No authentication required. Exposure depends on which interfaces accept traffic - internet-facing VPN and admin interfaces are the worst case, but a management VLAN is enough.

What to do

Upgrade to a fixed build per Fortinet FG-IR-25-084 (6.4.x is listed as affected with no fixed branch given in this record - treat those units as end-of-support and plan replacement or isolation). This is an appliance image upgrade and reboot, not a package update: schedule per HA member and fail over between them, and expect sessions to drop. Until the window, restrict which networks can reach the appliance's listening interfaces. Because the flaw is already exploited, review the device for signs of compromise before and after the upgrade rather than treating the upgrade as the whole remediation.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.