CVE-2025-53845
An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated attacker to obtain information pertaining to the dev
Severity
Medium 6.2
CVSS 3.1
Exploited
Not listed
EPSS
0.004
35.4th percentile
Discovered by
Not disclosed
Published
Oct 14, 2025
Assigned by fortinet
Description
An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated attacker to obtain information pertaining to the device's health and status, or cause a denial of service via crafted OFTP requests.
Weakness: CWE-287
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiAnalyzer | SIEM & Log Management | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiAnalyzer
Vendor remediation
Upgrade to FortiAnalyzer version 7.6.4 or above Upgrade to FortiAnalyzer version 7.4.7 or above