CVE-2025-67604

May 12, 2026, 6:57 p.m.

5.3
Medium

Description

A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker.

Product(s) Impacted

Vendor Product Versions
Fortinet
  • Fortianalyzer
  • Fortimanager
  • 7.6.0-7.6.4, 7.4.0-7.4.8, 7.2, 7.0, 6.4
  • 7.6.0-7.6.4, 7.4.0-7.4.8, 7.2, 7.0, 6.4

Weaknesses

Common security weaknesses mapped to this vulnerability.

CWE-676
Use of Potentially Dangerous Function
The product invokes a potentially dangerous function that could introduce a vulnerability if it is used incorrectly, but the function can also be used safely.

*CPE(s)

Affected systems and software identified for this CVE.

Type Vendor Product Version Update Edition Language Software Edition Target Software Target Hardware Other Information
a fortinet fortianalyzer 7.6.0-7.6.4 / / / / / / /
a fortinet fortianalyzer 7.4.0-7.4.8 / / / / / / /
a fortinet fortianalyzer 7.2 / / / / / / /
a fortinet fortianalyzer 7.0 / / / / / / /
a fortinet fortianalyzer 6.4 / / / / / / /
a fortinet fortimanager 7.6.0-7.6.4 / / / / / / /
a fortinet fortimanager 7.4.0-7.4.8 / / / / / / /
a fortinet fortimanager 7.2 / / / / / / /
a fortinet fortimanager 7.0 / / / / / / /
a fortinet fortimanager 6.4 / / / / / / /

CVSS Score

5.3 / 10

CVSS Data - 3.1

  • Attack Vector: NETWORK
  • Attack Complexity: HIGH
  • Privileges Required: LOW
  • Scope: UNCHANGED
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: HIGH
  • CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

    View Vector String

Timeline

Published: May 12, 2026, 6:16 p.m.
Last Modified: May 12, 2026, 6:57 p.m.

Status : Undergoing Analysis

CVE is currently being analyzed by NVD staff, this process results in association of reference link tags, CVSS scores, CWE association, and CPE applicability statements.

More info

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.