Impact
A buffer over-read vulnerability in Fortinet FortiOS allows an authenticated remote attacker to return a portion of device memory in the redirect response via a specially crafted request. The flaw can expose sensitive data from the device’s memory, representing a confidentiality breach. The weakness is identified as CWE-126.
Affected Systems
The affected products are Fortinet FortiOS 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, all 7.2.x releases, all 7.0.x releases, and all 6.4.x releases. Fortinet recommends moving to FortiOS 7.6.4 or higher, or to 7.4.9 or higher, to eliminate the flaw. Customers running FortiSASE are already remediated with version 25.4b, and those using FortiProxy should upgrade to 7.6.6 or higher, or to 7.4.14 for the 7.4 series.
Risk and Exploitability
The CVSS score of 4.1 and an EPSS score of less than 1% indicate low severity and low exploitation probability. The flaw requires authenticated access, limiting potential attackers to those with valid credentials or compromised accounts. Consequently, the overall risk is modest; however, an attacker with credentials could disclose memory contents, but the threat is lower than high‑severity data exfiltration or remote code execution.
OpenCVE Enrichment