PT-2025-15429 · Fortinet · Fortianalyzer+1

Published

2025-04-08

·

Updated

2025-07-23

·

CVE-2024-52962

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: FortiAnalyzer versions 7.6.1 and below FortiAnalyzer versions 7.4.5 and below FortiAnalyzer versions 7.2.8 and below FortiAnalyzer versions 7.0.13 and below FortiManager versions 7.6.1 and below FortiManager versions 7.4.5 and below FortiManager versions 7.2.8 and below FortiManager versions 7.0.12 and below
Description: An Improper Output Neutralization for Logs issue may allow an unauthenticated remote attacker to pollute the logs via crafted login requests.
Recommendations: For FortiAnalyzer versions 7.6.1 and below, consider updating to a version above 7.6.1. For FortiAnalyzer versions 7.4.5 and below, consider updating to a version above 7.4.5. For FortiAnalyzer versions 7.2.8 and below, consider updating to a version above 7.2.8. For FortiAnalyzer versions 7.0.13 and below, consider updating to a version above 7.0.13. For FortiManager versions 7.6.1 and below, consider updating to a version above 7.6.1. For FortiManager versions 7.4.5 and below, consider updating to a version above 7.4.5. For FortiManager versions 7.2.8 and below, consider updating to a version above 7.2.8. For FortiManager versions 7.0.12 and below, consider updating to a version above 7.0.12.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-09926
CVE-2024-52962

Affected Products

Fortianalyzer
Fortimanager