Executive brief
A security vulnerability exists in the SSL-VPN bookmarking feature of several Fortinet products, including FortiOS firewalls and FortiProxy web gateways. An authenticated user could exploit this flaw to execute unauthorized code on the system. This could lead to a complete compromise of the device, potentially allowing an attacker to intercept network traffic or gain a foothold within the corporate network.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in the RDP bookmark connection component of Fortinet's SSL-VPN functionality. The flaw is present in FortiOS, FortiPAM, and FortiProxy. An attacker must be authenticated to the SSL-VPN portal to exploit this vulnerability. By sending specially crafted requests through an RDP bookmark connection, the attacker can trigger the overflow to achieve arbitrary code execution. Fortinet has released firmware updates for affected branches (e.g., FortiOS 7.6.3, 7.4.8, 7.2.11) and provided virtual patches (FG-VD-60084.0day) for users with active security subscriptions.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10, 7.0 all versions, 6.4 all versions
- Fortinet FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions
- Fortinet FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.3, 7.2 all versions, 7.0 all versions
Timeline
- 2025-10-14: disclosed: Initial publication by Fortinet
- 2026-03-04: advisory: Updated with IPS package information