Fortinet has released updates to fix a critical security flaw affecting FortiSIEM that could allow an unauthorized attacker to execute code on vulnerable systems.

This is an OS injection vulnerability , tracked as CVE-2025-64155 , and has been rated 9.4/10.0 on the CVSS scoring system.
Fortinet said the vulnerability only affects Super and Worker nodes. The fixes have been released in the following versions:
- FortiSIEM 6.7.0 to 6.7.10 (Moving to fixed release)
- FortiSIEM 7.0.0 to 7.0.4 (Moving to fixed release)
- FortiSIEM 7.1.0 to 7.1.8 (Upgrade to 7.1.9 or later)
- FortiSIEM 7.2.0 to 7.2.6 (Upgrade to 7.2.7 or later)
- FortiSIEM 7.3.0 to 7.3.4 (Upgrade to 7.3.5 or later)
- FortiSIEM 7.4.0 (Upgrade to 7.4.1 or later)
- FortiSIEM 7.5 (Not affected)
- FortiSIEM Cloud (Not affected)
See also: Spring vulnerability allows commands to be executed on the user's PC
Horizon3.ai security researcher Zach Hanleydiscovered and reported the vulnerability on August 14, 2025. He stated that the vulnerability consists of two parts:
1. An “unauthenticated argument injection” vulnerability that leads to arbitrary file writing, allowing remote code execution as the admin user.
2. An overwrite privilege escalation vulnerability leading to root access and complete compromise of the device.

FortiSIEM: How vulnerability works
Specifically, the issue relates to how FortiSIEM's phMonitor service handles incoming requests related to logging security events to Elasticsearch .
See also: Critical vulnerability in Node.js can cause server crashes
This, in turn, calls a shell script with user-controlled parameters, thus opening the door for argument injection via curl and achieving arbitrary file writes to disk (in the context of the admin user).
This limited file writing can be used to completely take over the system by writing a reverse shell to “/opt/charting/redishb.sh”.

In other words, writing a reverse shell to this file allows privilege escalation from admin to root, giving the attacker unrestricted access to the FortiSIEM appliance. The most important element of the attack is that the phMonitor service exposes several command handlers that do not require authentication, making it easy for an attacker to invoke these functions simply by gaining network access on port 7900.
See also: Serious bug in Broadcom software allows WiFi denial of service
Users are advised to apply the latest updates for optimal protection. As workarounds for CVE-2025-64155, Fortinet recommends that customers restrict access to the phMonitor port (7900).
