CVE-2025-67604 Details
Description
A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker.
A vulnerability allowing denial-of-service conditions has been identified in Fortinet FortiAnalyzer and FortiManager. This issue affects multiple versions across different release branches. The vulnerability arises from a use of potentially dangerous functions in the API, which can be exploited by an authenticated attacker. By sending multiple specially crafted HTTP requests, the attacker can cause the system to hang and crash. This disruption occurs if internal locks are aligned, a condition that is not under the attacker's control.
Users can upgrade FortiAnalyzer to version 7.6.5 or 7.4.9, depending on their current version. FortiManager users should upgrade to the same respective versions. For FortiAnalyzer and FortiManager 7.2, users should migrate to a fixed release.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-137 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-676 | Use of Potentially Dangerous Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| fortinet fortianalyzer | >= 7.2.0, <= 7.2.12 >= 7.4.0, < 7.4.9 >= 7.6.0, < 7.6.5 |
CPE
Remediation
| |
| fortinet fortimanager | >= 7.2.0, <= 7.2.12 >= 7.4.0, < 7.4.9 >= 7.6.0, < 7.6.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 15, 2026 | Initial Analysis | [email protected] |
| May 12, 2026 | New CVE Received | [email protected] |