cbcvebase.
CVE-2025-54973
published 2025-10-14

CVE-2025-54973: A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0…

medium5.3CVSS 3.1
AVNACHPRNUIRSUCNIHAN
A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10 and before 7.0.13 allows an attacker to attempt to win a race condition to bypass the FortiCloud SSO authorization via crafted FortiCloud SSO requests.

Affected

11 ranges
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer>= 7.0.9 < 7.0.147.0.14
fortinetfortianalyzer7.0.9 – 7.0.13
fortinetfortianalyzer>= 7.2.0 < 7.2.117.2.11
fortinetfortianalyzer7.2.0 – 7.2.10
fortinetfortianalyzer>= 7.4.0 < 7.4.77.4.7
fortinetfortianalyzer7.4.0 – 7.4.6
fortinetfortianalyzer>= 7.6.0 < 7.6.37.6.3
fortinetfortianalyzer7.6.0 – 7.6.2
fortinetforticloud
fortinetfortinet