CVE-2025-64155 PUBLISHED

Assigner: fortinet
Reserved: 28.10.2025 Published: 13.01.2026 Updated: 26.02.2026

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C
CVSS Score: 9.4

Product Status

Vendor Fortinet
Product FortiSIEM
Versions Default: unaffected
  • Version 7.4.0 is affected
  • affected from 7.3.0 to 7.3.4 (incl.)
  • Version 7.2.6 is affected
  • Version 7.1.8 is affected
  • Version 7.0.4 is affected
  • Version 6.7.10 is affected

Solutions

Upgrade to FortiSIEM version 7.5.0 or above Upgrade to FortiSIEM version 7.4.1 or above Upgrade to FortiSIEM version 7.3.5 or above Upgrade to FortiSIEM version 7.2.7 or above Upgrade to FortiSIEM version 7.1.9 or above

References

Problem Types

  • Execute unauthorized code or commands CWE