cbcvebase.

Fortinet Fortianalyzer vulnerabilities

94 known vulnerabilities affecting fortinet/fortianalyzer.

Total CVEs
94
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH30MEDIUM51LOW7

Vulnerabilities

Page 3 of 5
CVE-2021-32603P3MEDIUMCVSS 6.5≥ 5.6.0, < 6.2.8≥ 6.4.0, < 6.4.6+1 more2021-08-05
CVE-2021-32603 [MEDIUM] CWE-918 CVE-2021-32603: A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7 A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker to access unauthorized files and services on the system via specifically crafted web requests.
nvd
CVE-2023-25609P3MEDIUMCVSS 6.5≥ 6.4.8, ≤ 6.4.11≥ 7.0.0, ≤ 7.0.6+3 more2023-06-13
CVE-2023-25609 [MEDIUM] CWE-918 CVE-2023-25609: A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7 A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.8 through 6.4.11 may allow a remote and authenticated attacker to access unauthorized files and services on the system via specially crafted web requests.
nvd
CVE-2023-41838P3HIGHCVSS 7.1≥ 6.2.0, ≤ 6.2.11≥ 6.4.0, ≤ 6.4.12+3 more2023-10-10
CVE-2023-41838 [HIGH] CWE-78 CVE-2023-41838: An improper neutralization of special elements used in an os command ('os command injection') in For An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow attacker to execute unauthorized code or commands via FortiManager cli.
nvd
CVE-2018-1354P3MEDIUMCVSS 6.5≤ 6.0.02018-06-27
CVE-2018-1354 [MEDIUM] CWE-732 CVE-2018-1354: An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, F An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content.
nvd
CVE-2024-32123P3MEDIUMCVSS 6.7≥ 6.2.0, < 7.2.6≥ 7.4.0, < 7.4.4+5 more2025-03-11
CVE-2024-32123 [MEDIUM] CWE-78 CVE-2024-32123: Multiple improper neutralization of special elements used in an os command ('os command injection') Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 and 5.6.0 through 5.6.11 and 5.4.0 through 5.4.7 and 5.2.0 throu
nvd
CVE-2025-53845P3MEDIUMCVSS 6.5≥ 6.4.0, < 7.4.7≥ 7.6.0, < 7.6.4+5 more2025-10-14
CVE-2025-53845 [MEDIUM] CWE-287 CVE-2025-53845: An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7 An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated attacker to obtain information pertaining to the device's health and status, or cause a denial of service via crafted OFTP requests.
nvd
CVE-2023-42788P3MEDIUMCVSS 6.7≥ 6.2.0, ≤ 6.2.11≥ 6.4.0, ≤ 6.4.12+3 more2023-10-10
CVE-2023-42788 [MEDIUM] CWE-78 CVE-2023-42788: An improper neutralization of special elements used in an os command ('OS Command Injection') vulner An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12 and version 6.2.0 through 6.2.11 may allow a local attacker with low privileges to execute unauthoriz
nvd
CVE-2023-44249P3MEDIUMCVSS 6.5≥ 6.2.0, ≤ 6.2.12≥ 6.4.0, ≤ 6.4.13+4 more2023-10-10
CVE-2023-44249 [MEDIUM] CWE-639 CVE-2023-44249: An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests.
nvd
CVE-2024-40585P3MEDIUMCVSS 6.5≥ 6.2.0, < 6.2.12≥ 6.4.0, < 6.4.13+7 more2025-03-14
CVE-2024-40585 [MEDIUM] CWE-532 CVE-2024-40585: An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager versio An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and below, version 6.2.11 and below and FortiAnalyzer version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and below, version 6.2.11 and below eventlo
nvd
CVE-2022-27490P3MEDIUMCVSS 6.5≥ 5.6.0, ≤ 5.6.11≥ 6.0.0, ≤ 6.0.42023-03-07
CVE-2022-27490 [MEDIUM] CWE-200 CVE-2022-27490: A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 through 6.0.4, FortiAnalyzer version 6.0.0 through 6.0.4, FortiPortal version 6.0.0 through 6.0.9, 5.3.0 through 5.3.8, 5.2.x, 5.1.0, 5.0.x, 4.2.x, 4.1.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.x, 6.0.x allows an attacker wh
nvd
CVE-2025-68482P3MEDIUMCVSS 5.9≥ 6.4.0, < 7.4.9≥ 7.6.0, < 7.6.5+5 more2026-03-10
CVE-2025-68482 [MEDIUM] CWE-295 CVE-2025-68482: A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, Forti A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versi
nvd
CVE-2023-25611P3HIGHCVSS 7.3≥ 6.4.0, < 7.0.6≥ 7.2.0, < 7.2.2+3 more2023-03-07
CVE-2023-25611 [HIGH] CWE-1236 CVE-2023-25611: A improper neutralization of formula elements in a CSV file vulnerability in Fortinet FortiAnalyzer A improper neutralization of formula elements in a CSV file vulnerability in Fortinet FortiAnalyzer 6.4.0 - 6.4.9, 7.0.0 - 7.0.5, and 7.2.0 - 7.2.1 allows local attacker to execute unauthorized code or commands via inserting spreadsheet formulas in macro names.
nvd
CVE-2024-31496P4MEDIUMCVSS 6.7≥ 6.2.0, < 7.2.6≥ 7.4.0, < 7.4.3+5 more2024-11-12
CVE-2024-31496 [MEDIUM] CWE-121 CVE-2024-31496: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized code or commands via crafted CLI requests.
nvd
CVE-2024-33501P4MEDIUMCVSS 6.7≥ 6.4.0, < 7.2.6≥ 7.4.0, < 7.4.32025-03-11
CVE-2024-33501 [MEDIUM] CWE-89 CVE-2024-33501: Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabili Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized
nvd
CVE-2023-41842P4MEDIUMCVSS 6.7≥ 6.2.0, < 7.0.10≥ 7.2.0, < 7.2.4+6 more2024-03-12
CVE-2023-41842 [MEDIUM] CWE-134 CVE-2023-41842: A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allo A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command arguments.
nvd
CVE-2023-42782P4MEDIUMCVSS 5.3≥ 6.2.0, ≤ 6.2.12≥ 6.4.0, ≤ 6.4.13+3 more2023-10-10
CVE-2023-42782 [MEDIUM] CWE-345 CVE-2023-42782: A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7. A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number.
nvd
CVE-2024-32117P4MEDIUMCVSS 4.9≥ 6.2.0, < 7.2.6≥ 7.4.0, < 7.4.3+5 more2024-11-12
CVE-2024-32117 [MEDIUM] CWE-22 CVE-2024-32117: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker to read arbitrary files from the und
nvd
CVE-2022-23439P4MEDIUMCVSS 6.1≥ 7.4.0, ≤ 7.4.2≥ 7.2.0, ≤ 7.2.11+3 more2025-01-22
CVE-2022-23439 [MEDIUM] CWE-610 CVE-2022-23439: A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
nvd
CVE-2022-26121P4MEDIUMCVSS 5.3≤ 5.6.11≤ 6.0.11+3 more2022-10-10
CVE-2022-26121 [MEDIUM] CWE-668 CVE-2022-26121: An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GU An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in the URL path.
nvd
CVE-2025-54973P4MEDIUMCVSS 5.3≥ 7.0.9, < 7.0.14≥ 7.2.0, < 7.2.11+6 more2025-10-14
CVE-2025-54973 [MEDIUM] CWE-362 CVE-2025-54973: A concurrent execution using shared resource with improper synchronization ('Race Condition') vulner A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10 and before 7.0.13 allows an attacker to attempt to win a race condition to bypass the FortiCloud SSO authorization via crafted FortiClou
nvd
Fortinet Fortianalyzer vulnerabilities | cvebase