Fortinet Fortianalyzer Big Data vulnerabilities

13 known vulnerabilities affecting fortinet/fortianalyzer_big_data.

Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM9LOW1

Vulnerabilities

Page 1 of 1
CVE-2025-49784HIGHCVSS 7.2≥ 6.2.1, < 7.4.5v7.6.02026-03-10
CVE-2025-49784 [MEDIUM] CWE-89 CVE-2025-49784: An improper neutralization of special elements used in an sql command ('sql injection') vulnerabilit An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer-BigData 7.6.0, FortiAnalyzer-BigData 7.4.0 through 7.4.4,
nvd
CVE-2024-32123MEDIUMCVSS 6.7≥ 6.4.5, < 7.2.8≥ 7.4.0, < 7.4.22025-03-11
CVE-2024-32123 [MEDIUM] CWE-78 CVE-2024-32123: Multiple improper neutralization of special elements used in an os command ('os command injection') Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 and 5.6.0 through 5.6.11 and 5.4.0 through 5.4.7 and 5.2.0 throu
nvd
CVE-2024-33501MEDIUMCVSS 6.7≥ 6.4.5, < 7.2.8v7.4.02025-03-11
CVE-2024-33501 [MEDIUM] CWE-89 CVE-2024-33501: Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabili Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized
nvd
CVE-2024-40584HIGHCVSS 7.2≥ 6.2.1, < 7.2.8v7.4.02025-02-11
CVE-2024-40584 [HIGH] CWE-78 CVE-2024-40584: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulner An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13
nvd
CVE-2024-23666HIGHCVSS 8.8≥ 6.2.1, < 7.2.7v7.4.02024-11-12
CVE-2024-23666 [HIGH] CWE-602 CVE-2024-23666: A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least versi A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7
nvd
CVE-2024-32117MEDIUMCVSS 4.9≥ 6.2.1, < 7.2.8v7.4.02024-11-12
CVE-2024-32117 [MEDIUM] CWE-22 CVE-2024-32117: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker to read arbitrary files from the und
nvd
CVE-2024-31496MEDIUMCVSS 6.7≥ 6.2.1, < 7.2.8v7.4.02024-11-12
CVE-2024-31496 [MEDIUM] CWE-121 CVE-2024-31496: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized code or commands via crafted CLI requests.
nvd
CVE-2023-44255MEDIUMCVSS 4.1≥ 6.2.1, < 7.2.62024-11-12
CVE-2023-44255 [MEDIUM] CWE-359 CVE-2023-44255: An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager bef An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.
nvd
CVE-2024-32116MEDIUMCVSS 6.0≥ 6.2.1, < 7.2.8v7.4.02024-11-12
CVE-2024-32116 [MEDIUM] CWE-23 CVE-2024-32116: Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 thr Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.
nvd
CVE-2024-32118MEDIUMCVSS 6.7≥ 6.2.1, < 7.2.8v7.4.02024-11-12
CVE-2024-32118 [MEDIUM] CWE-78 CVE-2024-32118: Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer-BigData before 7.4.0 allows an authenticated privileged attack
nvd
CVE-2024-35274LOWCVSS 2.3≥ 6.2.1, < 7.4.12024-11-12
CVE-2024-35274 [LOW] CWE-23 CVE-2024-35274: An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiAnalyzer versions below 7.4.2, Fortinet FortiManager versions below 7.4.2 and Fortinet FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker with read write administrative privileges to create non-arbitrary
nvd
CVE-2023-44254MEDIUMCVSS 6.5≥ 7.2.0, ≤ 7.2.52024-09-10
CVE-2023-44254 [MEDIUM] CWE-639 CVE-2023-44254: An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker with low privileges to read sensitive data via a crafted HTTP request.
nvd
CVE-2023-41842MEDIUMCVSS 6.7≥ 6.4.5, ≤ 6.4.7≥ 7.0.1, ≤ 7.0.6+2 more2024-03-12
CVE-2023-41842 [MEDIUM] CWE-134 CVE-2023-41842: A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allo A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command arguments.
nvd