Fortinet FortiOS Integer Overflow Vulnerability Leading to Denial-of-Service

Vulnerability

An integer overflow vulnerability has been identified in Fortinet FortiOS versions 7.2.0 through 7.2.7 and 7.0.0 through 7.0.14. This vulnerability may allow a remote, unauthenticated attacker to crash the 'csfd' daemon by sending a specially crafted request.

Impact

Exploitation of this vulnerability causes a denial-of-service condition by crashing the 'csfd' daemon.

Remediation

Users can upgrade to Fortinet FortiOS 7.2.8 or 7.0.15 or above, depending on their current version. Fortinet FortiOS 6.4 users should migrate to a fixed release.

Added: Jun 5, 2025, 11:41 PM
Updated: Jun 6, 2025, 12:15 AM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.