CVE-2025-64155: FortiSIEM Remote Unauthenticated Command Injection Vulnerability
ID: 00c00c51-c066-5cd9-bd1e-32d47d8e9fbc
STIX ID: report--00c00c51-c066-5cd9-bd1e-32d47d8e9fbc
Feed Name: Arctic Wolf
**Executive summary:** Fortinet released fixes for CVE-2025-64155, a critical unauthenticated command-injection vulnerability in FortiSIEM's phMonitor (TCP/7900) that can enable remote code execution, file write of reverse shells, and escalation from admin to root; a public PoC exists though Arctic Wolf has not observed in-the-wild exploitation. The advisory recommends immediate upgrades to listed fixed versions, isolating FortiSIEM from the internet, and restricting access to TCP/7900 as interim mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
