Fortinet fixed two critical flaws in FortiFone and FortiSIEM
ID: 095000d7-38fe-5de1-928e-62e6bea1fc0a
STIX ID: report--095000d7-38fe-5de1-928e-62e6bea1fc0a
Feed Name: Security Affairs
Fortinet released patches for six vulnerabilities, including two critical unauthenticated flaws: an OS command injection in FortiSIEM (CVE-2025-64155, CVSS 9.4) that can allow remote code execution via crafted TCP requests, and a sensitive-information exposure in the FortiFone web portal (CVE-2025-47855, CVSS 9.3) that can leak device configuration via crafted HTTP(S) requests; affected versions and fixed releases are listed and the vendor recommends patching (and limiting access to port 7900 for FortiSIEM) while noting that active exploitation has not been confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
