{"api_version":"1","generated_at":"2026-05-13T11:15:35+00:00","cve":"CVE-2025-67604","urls":{"html":"https://cve.report/CVE-2025-67604","api":"https://cve.report/api/cve/CVE-2025-67604.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-67604","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-67604"},"summary":{"title":"CVE-2025-67604","description":"A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker.","state":"PUBLISHED","assigner":"fortinet","published_at":"2026-05-12 18:16:36","updated_at":"2026-05-12 18:57:02"},"problem_types":["CWE-676","CWE-676 Denial of service"],"metrics":[{"version":"3.1","source":"psirt@fortinet.com","type":"Secondary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.2","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:F/RL:O/RC:C","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":5.2,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:F/RL:O/RC:C","version":"3.1"}}],"references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-137","name":"https://fortiguard.fortinet.com/psirt/FG-IR-26-137","refsource":"psirt@fortinet.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-67604","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67604","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Fortinet","product":"FortiAnalyzer","version":"affected 7.6.0 7.6.4 semver","platforms":[]},{"source":"CNA","vendor":"Fortinet","product":"FortiAnalyzer","version":"affected 7.4.0 7.4.8 semver","platforms":[]},{"source":"CNA","vendor":"Fortinet","product":"FortiAnalyzer","version":"affected 7.2.0 7.2.12 semver","platforms":[]},{"source":"CNA","vendor":"Fortinet","product":"FortiAnalyzer","version":"affected 7.0.0 7.0.16 semver","platforms":[]},{"source":"CNA","vendor":"Fortinet","product":"FortiAnalyzer","version":"affected 6.4.0 6.4.15 semver","platforms":[]},{"source":"CNA","vendor":"Fortinet","product":"FortiManager","version":"affected 7.6.0 7.6.4 semver","platforms":[]},{"source":"CNA","vendor":"Fortinet","product":"FortiManager","version":"affected 7.4.0 7.4.8 semver","platforms":[]},{"source":"CNA","vendor":"Fortinet","product":"FortiManager","version":"affected 7.2.0 7.2.12 semver","platforms":[]},{"source":"CNA","vendor":"Fortinet","product":"FortiManager","version":"affected 7.0.0 7.0.16 semver","platforms":[]},{"source":"CNA","vendor":"Fortinet","product":"FortiManager","version":"affected 6.4.0 6.4.15 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Upgrade to FortiAnalyzer version 8.0.0 or above\nUpgrade to FortiAnalyzer version 7.6.5 or above\nUpgrade to FortiAnalyzer version 7.4.9 or above\nUpgrade to FortiWeb version 8.0.3 or above\nUpgrade to FortiWeb version 7.6.7 or above\nUpgrade to FortiManager version 8.0.0 or above\nUpgrade to FortiManager version 7.6.5 or above\nUpgrade to FortiManager version 7.4.9 or above\nUpgrade to upcoming  FortiVoice version 8.0.0 or above\nUpgrade to upcoming  FortiVoice version 7.4.2 or above\nUpgrade to upcoming  FortiSandbox version 5.2.0 or above\nUpgrade to FortiSandbox version 5.0.6 or above","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:o:fortinet:fortianalyzer:7.6.4:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.6.3:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.6.2:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.6.1:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.6.0:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.4.8:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.4.7:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.4.6:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.4.5:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.4.4:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.4.3:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.4.2:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.4.1:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.4.0:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.2.12:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.2.11:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.2.10:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.2.9:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.2.8:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.2.7:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.2.6:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.2.5:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.2.4:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.2.3:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.2.2:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.2.1:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.2.0:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.16:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.15:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.14:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.13:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.12:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.11:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.10:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.9:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.8:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.7:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.6:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.5:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.4:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.3:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.2:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.1:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:7.0.0:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:6.4.15:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:6.4.14:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:6.4.13:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:6.4.12:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:6.4.11:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:6.4.10:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:6.4.9:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:6.4.8:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:6.4.7:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:6.4.6:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:6.4.5:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:6.4.4:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:6.4.3:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:6.4.2:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:6.4.1:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortianalyzer:6.4.0:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","product":"FortiAnalyzer","vendor":"Fortinet","versions":[{"lessThanOrEqual":"7.6.4","status":"affected","version":"7.6.0","versionType":"semver"},{"lessThanOrEqual":"7.4.8","status":"affected","version":"7.4.0","versionType":"semver"},{"lessThanOrEqual":"7.2.12","status":"affected","version":"7.2.0","versionType":"semver"},{"lessThanOrEqual":"7.0.16","status":"affected","version":"7.0.0","versionType":"semver"},{"lessThanOrEqual":"6.4.15","status":"affected","version":"6.4.0","versionType":"semver"}]},{"cpes":["cpe:2.3:o:fortinet:fortimanager:7.6.4:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.6.3:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.6.2:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.6.1:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.6.0:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.4.8:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.4.7:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.4.6:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.4.5:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.4.4:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.4.3:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.4.2:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.4.1:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.4.0:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.12:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.11:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.10:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.9:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.8:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.7:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.6:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.5:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.4:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.3:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.2:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.1:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.0:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.16:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.15:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.14:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.13:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.12:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.11:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.10:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.9:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.8:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.7:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.6:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.5:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.4:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.3:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.2:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.1:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.0.0:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:6.4.15:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:6.4.14:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:6.4.13:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:6.4.12:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:6.4.11:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:6.4.10:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:6.4.9:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:6.4.8:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:6.4.7:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:6.4.6:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:6.4.5:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:6.4.4:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:6.4.3:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:6.4.2:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:6.4.1:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:6.4.0:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","product":"FortiManager","vendor":"Fortinet","versions":[{"lessThanOrEqual":"7.6.4","status":"affected","version":"7.6.0","versionType":"semver"},{"lessThanOrEqual":"7.4.8","status":"affected","version":"7.4.0","versionType":"semver"},{"lessThanOrEqual":"7.2.12","status":"affected","version":"7.2.0","versionType":"semver"},{"lessThanOrEqual":"7.0.16","status":"affected","version":"7.0.0","versionType":"semver"},{"lessThanOrEqual":"6.4.15","status":"affected","version":"6.4.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","value":"A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":5.2,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:F/RL:O/RC:C","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-676","description":"Denial of service","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-05-12T16:54:11.929Z","orgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","shortName":"fortinet"},"references":[{"name":"https://fortiguard.fortinet.com/psirt/FG-IR-26-137","url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-137"}],"solutions":[{"lang":"en","value":"Upgrade to FortiAnalyzer version 8.0.0 or above\nUpgrade to FortiAnalyzer version 7.6.5 or above\nUpgrade to FortiAnalyzer version 7.4.9 or above\nUpgrade to FortiWeb version 8.0.3 or above\nUpgrade to FortiWeb version 7.6.7 or above\nUpgrade to FortiManager version 8.0.0 or above\nUpgrade to FortiManager version 7.6.5 or above\nUpgrade to FortiManager version 7.4.9 or above\nUpgrade to upcoming  FortiVoice version 8.0.0 or above\nUpgrade to upcoming  FortiVoice version 7.4.2 or above\nUpgrade to upcoming  FortiSandbox version 5.2.0 or above\nUpgrade to FortiSandbox version 5.0.6 or above"}]}},"cveMetadata":{"assignerOrgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","assignerShortName":"fortinet","cveId":"CVE-2025-67604","datePublished":"2026-05-12T16:54:11.929Z","dateReserved":"2025-12-09T14:59:55.699Z","dateUpdated":"2026-05-12T16:54:11.929Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-05-12 18:16:36","lastModifiedDate":"2026-05-12 18:57:02","problem_types":["CWE-676","CWE-676 Denial of service"],"metrics":{"cvssMetricV31":[{"source":"psirt@fortinet.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":3.6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"67604","Ordinal":"1","Title":"CVE-2025-67604","CVE":"CVE-2025-67604","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"67604","Ordinal":"1","NoteData":"A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker.","Type":"Description","Title":"CVE-2025-67604"}]}}}