Fortinet Fortianalyzer vulnerabilities
94 known vulnerabilities affecting fortinet/fortianalyzer.
Total CVEs
94
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH30MEDIUM51LOW7
Vulnerabilities
Page 4 of 5
CVE-2021-43072P4MEDIUMCVSS 6.7≥ 5.6.0, < 6.4.8≥ 7.0.0, < 7.0.3+5 more2023-07-18
CVE-2021-43072 [MEDIUM] CWE-120 CVE-2021-43072: A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer v
A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6.11 and below, FortiManager version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6
nvd
CVE-2025-67604P4MEDIUMCVSS 5.3≥ 7.2.0, ≤ 7.2.12≥ 7.4.0, < 7.4.9+5 more2026-05-12
CVE-2025-67604 [MEDIUM] CWE-676 CVE-2025-67604: A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4,
A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all
nvd
CVE-2024-52962P4MEDIUMCVSS 5.3≥ 7.0.0, < 7.0.14≥ 7.2.0, < 7.2.9+6 more2025-04-08
CVE-2024-52962 [MEDIUM] CWE-117 CVE-2024-52962: An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 an
An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.13 and below and FortiManager version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.12 and below may allow an unauthenticated remote attacker to po
nvd
CVE-2021-42757P4MEDIUMCVSS 6.7≥ 6.0.0, ≤ 6.4.7≥ 7.0.0, ≤ 7.0.2+2 more2021-12-08
CVE-2021-42757 [MEDIUM] CWE-120 CVE-2021-42757: A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 thr
A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
nvd
CVE-2022-26118P4MEDIUMCVSS 6.7≥ 6.0.0, ≤ 6.0.11≥ 6.2.0, ≤ 6.2.9+2 more2022-07-18
CVE-2022-26118 [MEDIUM] CWE-269 CVE-2022-26118: A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 t
A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.
nvd
CVE-2024-32116P4MEDIUMCVSS 6.0≥ 6.2.0, < 7.2.6≥ 7.4.0, < 7.4.3+5 more2024-11-12
CVE-2024-32116 [MEDIUM] CWE-23 CVE-2024-32116: Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 thr
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.
nvd
CVE-2024-36508P4MEDIUMCVSS 6.0≥ 6.4.0, < 7.2.6≥ 7.4.0, < 7.4.3+4 more2025-02-11
CVE-2024-36508 [MEDIUM] CWE-22 CVE-2024-36508: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose privileges to delete files on the system.
nvd
CVE-2021-24021P4MEDIUMCVSS 5.4≥ 6.0.0, < 6.2.8≥ 6.4.0, < 6.4.42021-10-06
CVE-2021-24021 [MEDIUM] CWE-79 CVE-2021-24021: An improper neutralization of input vulnerability [CWE-79] in FortiAnalyzer versions 6.4.3 and below
An improper neutralization of input vulnerability [CWE-79] in FortiAnalyzer versions 6.4.3 and below, 6.2.7 and below and 6.0.10 and below may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the column settings of Logview in FortiAnalyzer, should the attacker be able to obtain that POST request, via oth
nvd
CVE-2018-1355P4MEDIUMCVSS 6.1≤ 5.6.5v6.0.02018-06-27
CVE-2018-1355 [MEDIUM] CWE-601 CVE-2018-1355: An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyz
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing
nvd
CVE-2022-30304P4MEDIUMCVSS 6.1≥ 6.0.0, ≤ 6.0.11≥ 6.2.0, ≤ 6.2.9+7 more2023-02-16
CVE-2022-30304 [MEDIUM] CWE-79 CVE-2022-30304: An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyz
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer versions prior to 7.2.1, 7.0.4 and 6.4.8 may allow a remote unauthenticated attacker to perform a stored cross site scripting (XSS) attack via the URL parameter observed in the FortiWeb attack event logview in FortiAnalyzer.
nvd
CVE-2018-13375P4MEDIUMCVSS 6.1≤ 5.6.0vFortiAnalyzer 5.6.0 and below2019-05-28
CVE-2018-13375 [MEDIUM] CWE-79 CVE-2018-13375: An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and
An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 and below allows an attacker to send DHCP request containing malicious scripts in the HOSTNAME parameter. The malicious script code is executed while viewing the logs in FortiAnalyzer and FortiManager (with FortiAnalyzer feature ena
nvd
CVE-2023-40719P4MEDIUMCVSS 5.5≥ 7.0.0, ≤ 7.0.10≥ 7.2.0, ≤ 7.2.3+1 more2023-11-14
CVE-2023-40719 [MEDIUM] CWE-798 CVE-2023-40719: A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0
A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 and 7.4.0 allows an attacker to access Fortinet private testing data via the use of static credentials.
nvd
CVE-2023-44253P4MEDIUMCVSS 5.0≥ 6.2.0, ≤ 6.2.12≥ 6.4.0, ≤ 6.4.14+5 more2024-02-15
CVE-2023-44253 [MEDIUM] CWE-200 CVE-2023-44253: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet Fo
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allows an adom administrator to enumerate other adoms and device names via crafted HTTP or HTTPS
nvd
CVE-2022-39950P4MEDIUMCVSS 5.4≥ 6.0.0, ≤ 6.2.9≥ 6.4.0, ≤ 6.4.8+1 more2022-11-02
CVE-2022-39950 [MEDIUM] CVE-2022-39950: An improper neutralization of input during web page generation vulnerability [CWE-79] exists in Fort
An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor "protected" comment as described
nvd
CVE-2021-32597P4MEDIUMCVSS 5.4fixed in 6.2.8≥ 6.4.0, < 6.4.6+1 more2021-08-06
CVE-2021-32597 [MEDIUM] CWE-79 CVE-2021-32597: Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and Fo
Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions 7.0.0, 6.4.5 and below, 6.2.7 and below user interface, may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious payload in GET parameters.
nvd
CVE-2020-12814P4MEDIUMCVSS 5.4≥ 6.0.0, ≤ 6.0.6v6.4.42021-11-02
CVE-2020-12814 [MEDIUM] CWE-79 CVE-2020-12814: A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet F
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiAnalyzer version 6.0.6 and below, version 6.4.4 allows attacker to execute unauthorized code or commands via specifically crafted requests to the web GUI.
nvd
CVE-2020-12811P4MEDIUMCVSS 6.1≥ 6.2.0, ≤ 6.2.62020-09-24
CVE-2020-12811 [MEDIUM] CWE-79 CVE-2020-12811: An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6
An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6.2.2, and 6.2.3and FortiAnalyzer 6.2.0, 6.2.1, 6.2.2, and 6.2.3 may allow an attacker to execute a cross site scripting (XSS) via the Identify Provider name field.
nvd
CVE-2022-42477P4MEDIUMCVSS 5.5≥ 6.4.0, < 7.0.7v7.2.0+3 more2023-04-11
CVE-2022-42477 [MEDIUM] CWE-20 CVE-2022-42477: An improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, versio
An improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6.4 all versions may allow an authenticated attacker to disclose file system information via custom dataset SQL queries.
nvd
CVE-2020-6640P4MEDIUMCVSS 5.4fixed in 6.2.42020-06-04
CVE-2020-6640 [MEDIUM] CWE-79 CVE-2020-6640: An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a
An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Description Area.
nvd
CVE-2020-12815P4MEDIUMCVSS 5.4≤ 6.2.5≥ 6.4.0, ≤ 6.4.12020-09-24
CVE-2020-12815 [MEDIUM] CWE-79 CVE-2020-12815: An improper neutralization of input vulnerability in FortiTester before 3.9.0 may allow a remote aut
An improper neutralization of input vulnerability in FortiTester before 3.9.0 may allow a remote authenticated attacker to inject script related HTML tags via IPv4/IPv6 address fields.
nvd