Description
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.
Published: 2026-07-14
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer over-read vulnerability in Fortinet FortiOS allows an authenticated remote attacker to return a portion of device memory in the redirect response via a specially crafted request. The flaw can expose sensitive data from the device’s memory, representing a confidentiality breach. The weakness is identified as CWE-126.

Affected Systems

The affected products are Fortinet FortiOS 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, all 7.2.x releases, all 7.0.x releases, and all 6.4.x releases. Fortinet recommends moving to FortiOS 7.6.4 or higher, or to 7.4.9 or higher, to eliminate the flaw. Customers running FortiSASE are already remediated with version 25.4b, and those using FortiProxy should upgrade to 7.6.6 or higher, or to 7.4.14 for the 7.4 series.

Risk and Exploitability

The CVSS score of 4.1 and an EPSS score of less than 1% indicate low severity and low exploitation probability. The flaw requires authenticated access, limiting potential attackers to those with valid credentials or compromised accounts. Consequently, the overall risk is modest; however, an attacker with credentials could disclose memory contents, but the threat is lower than high‑severity data exfiltration or remote code execution.

Generated by OpenCVE AI on July 31, 2026 at 10:08 UTC.

Remediation

Vendor Solution

Upgrade to FortiOS version 7.6.4 or above Upgrade to FortiOS version 7.4.9 or above Fortinet remediated this issue in FortiSASE version 25.4.b and hence customers do not need to perform any action. Upgrade to FortiProxy version 7.6.6 or above Upgrade to FortiProxy version 7.4.14 or above


OpenCVE Recommended Actions

  • Upgrade FortiOS to version 7.6.4 or higher, or to 7.4.9 if on the 7.4 series, to apply the vendor fix.
  • For FortiProxy deployments, upgrade to version 7.6.6 or higher, or to 7.4.14 for 7.4.x to secure against the over‑read vulnerability.
  • Implement network segmentation to isolate management interfaces, limiting potential attacker reach to authenticated credentials.
  • No action required for FortiSASE customers using version 25.4b; the issue is already remediated.

Generated by OpenCVE AI on July 31, 2026 at 10:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Buffer Over‑Read in FortiOS Redirect Response

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Buffer Over‑Read in FortiOS Redirect Response

Fri, 24 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Buffer Over-Read in FortiOS Leading to Memory Disclosure

Fri, 17 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Buffer Over-Read in FortiOS Leading to Memory Disclosure

Thu, 16 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.

Tue, 14 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.
First Time appeared Fortinet
Fortinet fortios
Weaknesses CWE-126
CPEs cpe:2.3:o:fortinet:fortios:7.0.0:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.10:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.11:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.12:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.13:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.14:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.15:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.16:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.17:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.18:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.19:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.1:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.2:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.3:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.4:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.5:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.6:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.7:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.8:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.9:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.2.0:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.2.10:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.2.11:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.2.12:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.2.13:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.2.1:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.2.2:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.2.3:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.2.4:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.2.5:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.2.6:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.2.7:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.2.8:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.2.9:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.4.0:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.4.1:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.4.2:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.4.3:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortios
References
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}


Subscriptions

Fortinet Fortios
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-07-16T14:00:36.002Z

Reserved: 2025-04-18T14:46:53.847Z

Link: CVE-2025-43892

cve-icon Vulnrichment

Updated: 2026-07-14T16:02:26.379Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:15:06Z

Weaknesses