5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N/E:X/RL:X/RC:C
Description
A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10 and before 7.0.13 allows an attacker to attempt to win a race condition to bypass the FortiCloud SSO authorization via crafted FortiCloud SSO requests.
Basic Information
ID
CVE-2025-54973
Source
fortinet
Published
Oct 14, 2025 at 15:23
Affected Product
Vendor
Fortinet
Product
FortiAnalyzer
Version
7.6.0
Affected Versions
Fortinet FortiAnalyzer 7.6.0
Fortinet FortiAnalyzer 7.4.0
Fortinet FortiAnalyzer 7.2.0
Fortinet FortiAnalyzer 7.0.9
Fortinet FortiAnalyzer 7.4.0
Fortinet FortiAnalyzer 7.2.0
Fortinet FortiAnalyzer 7.0.9