CVE-2025-53845

An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated attacker to obtain information pertaining to the dev

Severity
Medium 6.2
CVSS 3.1
Exploited
Not listed
EPSS
0.004
35.4th percentile
Discovered by
Not disclosed
Published
Oct 14, 2025
Assigned by fortinet

Description

An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated attacker to obtain information pertaining to the device's health and status, or cause a denial of service via crafted OFTP requests.

Weakness: CWE-287

Affected products

Vendor Product Category Matched by
Fortinet FortiAnalyzer SIEM & Log Management cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiAnalyzer

Vendor remediation

Upgrade to FortiAnalyzer version 7.6.4 or above Upgrade to FortiAnalyzer version 7.4.7 or above