Description
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.
Related CPE's
a
fortinet
fortisiem
4
References
https://fortiguard.fortinet.com/psirt/FG-IR-25-772
Vendor Advisory
https://github.com/horizon3ai/CVE-2025-64155
ExploitThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 · Critical
Information
Source identifier
Vulnerability status
Analyzed
Published
2026-01-13T17:15:58.440Z
34 hours agoLast modified
2026-01-14T21:37:40.197Z
6 hours ago