PT-2025-41957 · Fortinet · Fortianalyzer

Published

2025-10-14

·

Updated

2025-10-15

·

CVE-2025-53845

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Fortinet FortiAnalyzer versions 7.6.0 through 7.6.3 Fortinet FortiAnalyzer versions prior to 7.4.6
Description An improper authentication issue exists in FortiAnalyzer. An unauthenticated attacker can obtain information about the device’s health and status, or cause a denial of service by sending specially crafted OFTP requests.
Recommendations Update FortiAnalyzer to a version later than 7.6.3. Update FortiAnalyzer to version 7.4.6 or later.

Fix

DoS

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-14795
CVE-2025-53845

Affected Products

Fortianalyzer