cbcvebase.

Fortinet Fortianalyzer vulnerabilities

94 known vulnerabilities affecting fortinet/fortianalyzer.

Total CVEs
94
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH30MEDIUM51LOW7

Vulnerabilities

Page 2 of 5
CVE-2023-22642P3HIGHCVSS 8.1≥ 6.4.8, < 6.4.11≥ 7.0.0, < 7.0.6+5 more2023-04-11
CVE-2023-22642 [HIGH] CWE-295 CVE-2023-22642: An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 t An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressourc
nvd
CVE-2024-36512P3HIGHCVSS 7.2≥ 6.2.10, < 7.0.13≥ 7.2.0, < 7.2.6+5 more2025-01-14
CVE-2024-36512 [HIGH] CWE-22 CVE-2024-36512: An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiM An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 through 7.0.12 and 6.2.10 through 6.2.13 allows attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.
nvd
CVE-2024-26013P3HIGHCVSS 7.5≥ 6.2.0, < 6.2.14≥ 6.4.0, < 6.4.15+3 more2025-04-08
CVE-2024-26013 [HIGH] CWE-923 CVE-2024-26013: A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in For A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9 and before 7.0.15, Fortinet FortiManager version 7.4.0 thr
nvd
CVE-2025-68648P3HIGHCVSS 7.2≥ 7.0.0, < 7.4.8≥ 7.6.0, < 7.6.5+4 more2026-03-10
CVE-2025-68648 [HIGH] CWE-134 CVE-2025-68648: A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7 A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, Fort
nvd
CVE-2025-48418P3HIGHCVSS 7.2≥ 6.4.0, < 7.0.15≥ 7.2.0, < 7.2.11+7 more2026-03-10
CVE-2025-48418 [HIGH] CWE-912 CVE-2025-48418: A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7. A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 through 7.2.10, FortiAnalyzer 7.0.0 through 7.0.14, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7, FortiAnalyzer Cloud 7.2.1 through 7.2.10, FortiAnalyzer Cloud
nvd
CVE-2024-33502P3HIGHCVSS 7.2≥ 6.0.0, < 7.2.6≥ 7.4.0, < 7.4.3+6 more2025-01-14
CVE-2024-33502 [HIGH] CWE-22 CVE-2024-33502: An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiM An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 allows attacker to execute unauthorized code or commands via crafted HTTP or HT
nvd
CVE-2024-50565P3HIGHCVSS 7.5≥ 6.2.0, < 6.2.14≥ 6.4.0, < 6.4.15+8 more2025-04-08
CVE-2024-50565 [HIGH] CWE-300 CVE-2024-50565: A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in For A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.15 and 2.0.0 through 2.0.14, For
nvd
CVE-2020-9289P3HIGHCVSS 7.5≤ 6.2.32020-06-16
CVE-2020-9289 [HIGH] CWE-798 CVE-2020-9289: Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive data, via knowledge of the hard-coded key.
nvd
CVE-2024-45331P3HIGHCVSS 7.8≥ 6.4.0, < 7.2.6≥ 7.4.0, < 7.4.4+4 more2025-01-16
CVE-2024-45331 [HIGH] CWE-266 CVE-2024-45331: A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiA A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.2, FortiAnalyzer Cloud 7.2.1 through 7.2.6, FortiAnalyzer Cloud 7.0 all versions, FortiAnalyzer Cloud 6.4 all versions, Fo
nvd
CVE-2024-21757P3HIGHCVSS 7.8≥ 7.0.0, < 7.0.11≥ 7.2.0, < 7.2.5+4 more2024-08-13
CVE-2024-21757 [HIGH] CWE-620 CVE-2024-21757: A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration ba
nvd
CVE-2024-33505P3HIGHCVSS 7.3≥ 6.4.0, < 7.2.6≥ 7.4.0, < 7.4.3+4 more2024-11-12
CVE-2024-33505 [HIGH] CWE-122 CVE-2024-33505: A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7. A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specially crafted http requests
nvd
CVE-2024-45330P3HIGHCVSS 7.2≥ 7.2.2, ≤ 7.2.5≥ 7.4.0, ≤ 7.4.32024-10-08
CVE-2024-45330 [HIGH] CWE-134 CVE-2024-45330: A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted requests.
nvd
CVE-2024-33503P3HIGHCVSS 7.8≥ 6.4.0, < 7.2.6≥ 7.4.0, < 7.4.42025-01-14
CVE-2024-33503 [HIGH] CWE-266 CVE-2024-33503: A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, Fo A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager Cloud 7.0 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions allows attacker to escalation of privilege via sp
nvd
CVE-2023-25606P3MEDIUMCVSS 6.5≥ 6.4.0, < 6.4.12≥ 7.0.0, ≤ 7.0.5+3 more2023-07-11
CVE-2023-25606 [MEDIUM] CWE-22 CVE-2023-25606: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4 all versions may allow a remote and authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web re
nvd
CVE-2025-68649P3MEDIUMCVSS 6.5≥ 7.0.0, < 7.4.8≥ 7.6.0, < 7.6.5+4 more2026-04-14
CVE-2025-68649 [MEDIUM] CWE-22 CVE-2025-68649: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in F An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.7, FortiAnalyzer Cloud 7.2 all
nvd
CVE-2023-44256P3MEDIUMCVSS 6.5≥ 6.4.8, ≤ 6.4.13≥ 7.0.2, ≤ 7.0.8+2 more2023-10-20
CVE-2023-44256 [MEDIUM] CWE-22 CVE-2023-44256: A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, versi A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and FortiManager version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 allows a remote attacker with low privileges to view sensitive data from internal servers or perform a local port scan via a crafted HT
nvd
CVE-2023-44254P3MEDIUMCVSS 6.5≥ 6.2.0, < 7.2.5v7.4.0+4 more2024-09-10
CVE-2023-44254 [MEDIUM] CWE-639 CVE-2023-44254: An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker with low privileges to read sensitive data via a crafted HTTP request.
nvd
CVE-2019-17657P3HIGHCVSS 7.5fixed in 6.2.3vbelow 6.2.32020-04-07
CVE-2019-17657 [HIGH] CWE-400 CVE-2019-17657: An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6 An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via handling special crafted HTTP requests/responses in pieces slowly, as demonstrated by Slow HTTP
nvd
CVE-2023-42787P3MEDIUMCVSS 6.5≥ 6.2.0, ≤ 6.2.12≥ 6.4.0, ≤ 6.4.13+3 more2023-10-10
CVE-2023-42787 [MEDIUM] CWE-602 CVE-2023-42787: A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager v A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.
nvd
CVE-2024-32118P3MEDIUMCVSS 6.7≥ 6.2.0, < 7.2.6≥ 7.4.0, < 7.4.3+5 more2024-11-12
CVE-2024-32118 [MEDIUM] CWE-78 CVE-2024-32118: Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer-BigData before 7.4.0 allows an authenticated privileged attack
nvd