PT-2026-24237 · Fortinet · Fortianalyzer+1

Published

2026-03-10

·

Updated

2026-03-17

·

CVE-2025-68482

CVSS v3.1

6.9

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiAnalyzer versions 6.4 through 7.6.4 Fortinet FortiManager versions 6.4 through 7.6.4
Description An incorrect certificate validation issue exists in Fortinet FortiAnalyzer and FortiManager. This flaw could allow a remote, unauthenticated attacker to view confidential information through a man-in-the-middle (MITM) attack. The issue stems from errors in the certificate authentication process.
Recommendations Fortinet FortiAnalyzer version 6.4 through 7.6.4: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Fortinet FortiManager version 6.4 through 7.6.4: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2026-03206
CVE-2025-68482

Affected Products

Fortianalyzer
Fortimanager