CVE-2025-64155: Critical FortiSIEM Flaw Allows Remote Root Access
ID: 811148df-3e8f-5854-a115-5a0d4fcf4546
STIX ID: report--811148df-3e8f-5854-a115-5a0d4fcf4546
Feed Name: SOCRadar Blog
Threat Score
Fortinet FortiSIEM is affected by a critical unauthenticated OS command injection (CVE-2025-64155, CVSS 9.8) in the phMonitor service (TCP 7900) that can lead to remote code execution and full system compromise via a writable admin-run script escalated to root; multiple 6.7.x–7.4.0 versions are impacted, Fortinet has released patches and guidance, a public PoC exists, and interim mitigation includes restricting access to port 7900 and reviewing logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
