B
今週中
FortinetのFortiOSおよびFortiSwitchManagerに、認証なしでリモートコード実行(RCE)が可能な深刻な脆弱性(CVE-2025-25…
📌 一言でいうと
FortinetのFortiOSおよびFortiSwitchManagerに、認証なしでリモートコード実行(RCE)が可能な深刻な脆弱性(CVE-2025-25249)が発見されました。この脆弱性を悪用して、PivotC2 RATをインストールし、ネットワークの偵察や設定情報の収集を行う攻撃が実際に確認されています。影響を受けるユーザーは、直ちに最新の修正済みバージョンへのアップデートを行うことが推奨されています。
🔍該当判定
- Fortinet社の製品(FortiGateなど)で、OSに『FortiOS』を利用している
- Fortinet社の製品で、『FortiSwitchManager』を利用している
- 社外からアクセス可能な状態で、上記Fortinet製品を運用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
影響を受けるFortinet製品(FortiOS, FortiSwitchManager)を最新の修正済みバージョンにアップデートし、不審な通信や設定変更がないかログを確認してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Fortinet FortiOS/FortiSwitchManager CVE-2025-25249 対応について
お疲れさまです。Fortinet製品の脆弱性に関する情報共有です。
■ 概要
FortiOSおよびFortiSwitchManagerにおいて、認証なしでリモートコード実行(RCE)が可能なHeap-based Buffer Overflowの脆弱性(CVE-2025-25249, CVSS 9.8)が確認されました。現在、この脆弱性を悪用してPivotC2 RATを感染させる実攻撃が観測されています。
■ 影響範囲
- Fortinet FortiOS
- FortiSwitchManager
■ 対応手順
1. 稼働中のバージョンを確認し、本脆弱性の影響を受けるか判定してください。
2. ベンダーが提供する最新の修正済みバージョンへ速やかにアップデートを適用してください。
3. PivotC2 RAT等の不審なプロセスや、外部への異常な通信がないかログを確認してください。
■ 参考情報
- ThaiCERT アドバイザリ
- Fortinet 公式セキュリティアドバイザリ
対応優先度: 高
対応期限: 至急
お疲れさまです。Fortinet製品の脆弱性に関する情報共有です。
■ 概要
FortiOSおよびFortiSwitchManagerにおいて、認証なしでリモートコード実行(RCE)が可能なHeap-based Buffer Overflowの脆弱性(CVE-2025-25249, CVSS 9.8)が確認されました。現在、この脆弱性を悪用してPivotC2 RATを感染させる実攻撃が観測されています。
■ 影響範囲
- Fortinet FortiOS
- FortiSwitchManager
■ 対応手順
1. 稼働中のバージョンを確認し、本脆弱性の影響を受けるか判定してください。
2. ベンダーが提供する最新の修正済みバージョンへ速やかにアップデートを適用してください。
3. PivotC2 RAT等の不審なプロセスや、外部への異常な通信がないかログを確認してください。
■ 参考情報
- ThaiCERT アドバイザリ
- Fortinet 公式セキュリティアドバイザリ
対応優先度: 高
対応期限: 至急
Subject: [Urgent] Action Required: Fortinet FortiOS/FortiSwitchManager CVE-2025-25249
Dear IT/Security Team,
We are sharing critical information regarding a vulnerability in Fortinet products.
■ Overview
A critical Heap-based Buffer Overflow vulnerability (CVE-2025-25249, CVSS 9.8) has been identified in FortiOS and FortiSwitchManager, allowing unauthenticated Remote Code Execution (RCE). Active exploitation has been detected, involving the deployment of the PivotC2 RAT for network reconnaissance and system control.
■ Affected Scope
- Fortinet FortiOS
- FortiSwitchManager
■ Mitigation Steps
1. Identify all deployed instances of FortiOS and FortiSwitchManager and check current versions.
2. Immediately update the affected devices to the latest patched versions provided by Fortinet.
3. Review system logs for signs of compromise, such as unauthorized configuration changes or unusual outbound traffic associated with PivotC2 RAT.
■ Reference
- ThaiCERT Advisory
- Fortinet Official Security Advisory
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing critical information regarding a vulnerability in Fortinet products.
■ Overview
A critical Heap-based Buffer Overflow vulnerability (CVE-2025-25249, CVSS 9.8) has been identified in FortiOS and FortiSwitchManager, allowing unauthenticated Remote Code Execution (RCE). Active exploitation has been detected, involving the deployment of the PivotC2 RAT for network reconnaissance and system control.
■ Affected Scope
- Fortinet FortiOS
- FortiSwitchManager
■ Mitigation Steps
1. Identify all deployed instances of FortiOS and FortiSwitchManager and check current versions.
2. Immediately update the affected devices to the latest patched versions provided by Fortinet.
3. Review system logs for signs of compromise, such as unauthorized configuration changes or unusual outbound traffic associated with PivotC2 RAT.
■ Reference
- ThaiCERT Advisory
- Fortinet Official Security Advisory
Priority: High
Deadline: Immediate