5.2
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:F/RL:O/RC:C
Description
A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker.
Basic Information
ID
CVE-2025-67604
Source
fortinet
Published
May 12, 2026 at 16:54
Affected Product
Vendor
Fortinet
Product
FortiAnalyzer
Version
7.6.0
Affected Versions
Fortinet FortiAnalyzer 7.6.0
Fortinet FortiAnalyzer 7.4.0
Fortinet FortiAnalyzer 7.2.0
Fortinet FortiAnalyzer 7.0.0
Fortinet FortiAnalyzer 6.4.0
Fortinet FortiManager 7.6.0
Fortinet FortiManager 7.4.0
Fortinet FortiManager 7.2.0
Fortinet FortiManager 7.0.0
Fortinet FortiManager 6.4.0
Fortinet FortiAnalyzer 7.4.0
Fortinet FortiAnalyzer 7.2.0
Fortinet FortiAnalyzer 7.0.0
Fortinet FortiAnalyzer 6.4.0
Fortinet FortiManager 7.6.0
Fortinet FortiManager 7.4.0
Fortinet FortiManager 7.2.0
Fortinet FortiManager 7.0.0
Fortinet FortiManager 6.4.0