Junglewise Threat Intelligence

CVE-2025-25248: Fortinet FortiOS and FortiProxy integer overflow in SSL-VPN bookmarks

CVE-2025-25248 · Severity: medium · CVSS 5.3 · Published 2025-08-12

Technologies: Fortinet Fortipam, Siemens Ruggedcom Ape1808, Fortinet FortiOS, Fortinet FortiGate NGFW, Fortinet FortiProxy. Vendors: Siemens, Fortinet.

Executive brief

A vulnerability exists in several Fortinet networking products, including FortiOS and FortiProxy, which provide secure remote access and firewall services. An authenticated user could exploit this flaw to crash the SSL-VPN service, preventing other employees from connecting to the corporate network. This impact is limited to service availability and does not directly result in the theft of sensitive data.

Technical details

An integer overflow or wraparound vulnerability (CWE-190) exists within the SSL-VPN RDP and VNC bookmarking components of FortiOS, FortiProxy, and FortiPAM. The flaw is triggered when the system processes specially crafted requests related to these bookmarks. An attacker must be authenticated to the SSL-VPN portal to exploit this vulnerability. Successful exploitation allows the attacker to affect the availability of the SSL-VPN service, leading to a denial-of-service (DoS) condition. Fortinet has released patches for various branches, including FortiOS 7.6.3, 7.4.8, and 7.2.11.

Affected products

  • Fortinet FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10, 7.0 all versions, 6.4 all versions
  • Fortinet FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.3, 7.2 all versions, 7.0 all versions, 2.0 all versions
  • Fortinet FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions
  • Siemens RUGGEDCOM APE1808 (Fortigate NGFW) Versions with Fortigate NGFW < V7.4.9

Timeline

  • 2025-08-12: disclosed: Initial publication by Fortinet
  • 2025-08-12: advisory: Fortinet advisory FG-IR-24-364 published

References

Related threats