Back to Rule

Rule History

SID: 2064027 • Source: et/open

Versions (2)

Version DetailsCurrent

Rev: 1Aug 15, 2025, 12:00 PM

ET EXPLOIT Fortinet FortiSIEM Unauthenticated phMonitor Command Injection (CVE-2025-25256)

alert tcp any any -> $HOME_NET 7900 (msg:"ET EXPLOIT Fortinet FortiSIEM Unauthenticated phMonitor Command Injection (CVE-2025-25256)"; flow:established,to_server; content:"|5a 00 00 00|"; startswith; content:"|3c|archive_nfs_archive_dir|3e|"; fast_pattern; pcre:"/^[^\x3e]*?(?:[\x3b\x24\x2\x60\x7c]|\x25(?:3[bB]|2[46]|60|7[cC]))/R"; reference:url,labs.watchtowr.com/should-security-solutions-be-secure-maybe-were-all-wrong-fortinet-fortisiem-pre-auth-command-injection-cve-2025-25256/; reference:cve,2025-25256; classtype:attempted-user; sid:2064027; rev:1; metadata:affected_product FortiSIEM, attack_target Networking_Equipment, tls_state TLSDecrypt, created_at 2025_08_15, cve CVE_2025_25256, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_08_15; target:dest_ip;)

Aug 15, 2025, 12:00 PM

Aug 15, 2025, 12:00 PM

Aug 15, 2025, 8:34 PM

Aug 18, 2025, 8:35 PM

rules/emerging-exploit.rules