Fortinet fixed two critical flaws in FortiFone and FortiSIEM
ID: 0531bece-8888-5295-ab6e-3433dd9459c8
STIX ID: report--0531bece-8888-5295-ab6e-3433dd9459c8
Feed Name: Security Affairs
Fortinet released patches for six vulnerabilities, including two critical unauthenticated flaws: CVE-2025-64155 (FortiSIEM — OS command injection enabling unauthenticated remote code execution via crafted TCP requests) and CVE-2025-47855 (FortiFone — unauthenticated exposure of device configuration via crafted HTTP/HTTPS requests). The advisory lists affected FortiSIEM and FortiFone versions and recommended upgrade paths, notes mitigation suggestions (e.g., limit access to phMonitor port 7900), identifies the reporting researchers, and states there is no clear evidence of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
