Fortinet FortiSIEM Vulnerability CVE-2025-64155 Actively Exploited in Attacks
A critical vulnerability identified as CVE-2025-64155 has been detected in Fortinet FortiSIEM systems. This vulnerability is currently under active exploitation and poses significant risks due to its ability to allow unauthenticated remote code execution…
A critical vulnerability identified as CVE-2025-64155 has been detected in Fortinet FortiSIEM systems. This vulnerability is currently under active exploitation and poses significant risks due to its ability to allow unauthenticated remote code execution through OS command injection.
The flaw is located in the FortiSIEM phMonitor service, which is responsible for internal data exchange across Super and Worker nodes. Attackers can exploit this vulnerability by sending specially crafted TCP requests to port 7900. These requests target storage configuration endpoints with an elastic type set, injecting arguments into a curl command via XML payloads. This results in arbitrary file writes with administrative privileges, and a chained privilege escalation can provide root access by overwriting executed binaries.
Proof-of-concept code is publicly available on GitHub , showcasing complete remote code execution chains. Fortinet has confirmed that Cloud and Collector nodes are not affected by this vulnerability.
Product Version Affected Range Fixed Version
FortiSIEM 6.7 6.7.0 through 6.7.10 Migrate to a fixed release
FortiSIEM 7.0 7.0.0 through 7.0.4 Migrate to a fixed release
FortiSIEM 7.1 7.1.0 through 7.1.8 7.1.9 or above
FortiSIEM 7.2 7.2.0 through 7.2.6 7.2.7 or above
FortiSIEM 7.3 7.3.0 through 7.3.4 7.3.5 or above
A critical vulnerability identified as CVE-2025-64155 has been detected in Fortinet FortiSIEM systems.
FortiSIEM 7.4 7.4.0 7.4.1 or above
FortiSIEM 7.5 Not affected N/A
FortiSIEM Cloud Not affected N/A
Exploitation attempts have been logged as PHL_ERROR entries in /opt/phoenix/log/phoenix.log, revealing attacker URLs and file paths. The unauthenticated nature of the flaw, along with the exposure of SIEM systems, increases the risk of log tampering, data exfiltration, or lateral movement.
Indicators of compromise include recent IP addresses involved in attacks:
IP Address ASN/Organization
167.17.179[.]109 Baxet Group Inc.
103.224.84[.]76 Siamdata Communication
209.126.11[.]25 Contabo
120.231.127[.]227 China Mobile Communications Group
129.226.190[.]169 Tencent
220.181.41[.]80 IDC, China Telecommunications Corporation
Organizations using FortiSIEM should upgrade Super/Worker nodes immediately according to Fortinet’s advisory . As a temporary measure, block external access to TCP port 7900. Monitoring phMonitor logs for irregularities and using endpoint detection and response (EDR) tools to scan for indicators of compromise (IOCs) is also advised.
Based on reporting by Cyber Security News.
