CVE-2025-67604
Summary
| CVE | CVE-2025-67604 |
|---|---|
| State | PUBLISHED |
| Assigner | fortinet |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-12 18:16:36 UTC |
| Updated | 2026-05-12 18:57:02 UTC |
| Description | A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-676 | CWE-676 Denial of service
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | CNA | CVSS | 5.2 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:F/RL:O/RC:C |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Fortinet | FortiAnalyzer | affected 7.6.0 7.6.4 semver | Not specified |
| CNA | Fortinet | FortiAnalyzer | affected 7.4.0 7.4.8 semver | Not specified |
| CNA | Fortinet | FortiAnalyzer | affected 7.2.0 7.2.12 semver | Not specified |
| CNA | Fortinet | FortiAnalyzer | affected 7.0.0 7.0.16 semver | Not specified |
| CNA | Fortinet | FortiAnalyzer | affected 6.4.0 6.4.15 semver | Not specified |
| CNA | Fortinet | FortiManager | affected 7.6.0 7.6.4 semver | Not specified |
| CNA | Fortinet | FortiManager | affected 7.4.0 7.4.8 semver | Not specified |
| CNA | Fortinet | FortiManager | affected 7.2.0 7.2.12 semver | Not specified |
| CNA | Fortinet | FortiManager | affected 7.0.0 7.0.16 semver | Not specified |
| CNA | Fortinet | FortiManager | affected 6.4.0 6.4.15 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fortiguard.fortinet.com/psirt/FG-IR-26-137 | [email protected] | fortiguard.fortinet.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
Solutions
CNA: Upgrade to FortiAnalyzer version 8.0.0 or above Upgrade to FortiAnalyzer version 7.6.5 or above Upgrade to FortiAnalyzer version 7.4.9 or above Upgrade to FortiWeb version 8.0.3 or above Upgrade to FortiWeb version 7.6.7 or above Upgrade to FortiManager version 8.0.0 or above Upgrade to FortiManager version 7.6.5 or above Upgrade to FortiManager version 7.4.9 or above Upgrade to upcoming FortiVoice version 8.0.0 or above Upgrade to upcoming FortiVoice version 7.4.2 or above Upgrade to upcoming FortiSandbox version 5.2.0 or above Upgrade to FortiSandbox version 5.0.6 or above