Potential Exploitation Risk in Fortinet FortiAnalyzer and FortiManager Products
CVE-2025-67604

5.2MEDIUM

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
12 May 2026

What is CVE-2025-67604?

A vulnerability in Fortinet FortiAnalyzer and FortiManager products allows authenticated attackers to cause a system hang by sending multiple specially crafted HTTP requests. This occurs due to misalignment of internal locks, impacting system stability and security. Organizations using affected versions should take immediate action to mitigate potential threats.

Affected Version(s)

FortiAnalyzer 7.6.0 <= 7.6.4

FortiAnalyzer 7.4.0 <= 7.4.8

FortiAnalyzer 7.2.0 <= 7.2.12

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.