Junglewise Threat Intelligence

CVE-2025-67604: Fortinet FortiAnalyzer and FortiManager DoS via unsafe function in API

CVE-2025-67604 · Severity: medium · CVSS 5.3 · Published 2026-05-12

Technologies: Fortinet FortiManager, Fortinet Fortianalyzer. Vendors: Fortinet.

Executive brief

Fortinet FortiAnalyzer and FortiManager, which are used for centralized network logging and management, are vulnerable to a denial-of-service issue. An authenticated user can send specific web requests that cause the system to crash or hang, potentially disrupting network monitoring and management operations. This issue requires specific internal timing conditions to be met, making it difficult to trigger reliably.

Technical details

A 'Use of Potentially Dangerous Function' vulnerability (CWE-676) exists in the API component of FortiAnalyzer and FortiManager. The issue specifically involves the use of an unsafe function within a signal handler. An authenticated attacker can exploit this by sending multiple specially crafted HTTP requests over the network. Successful exploitation leads to a system hang or crash, though the attack has high complexity as it depends on the alignment of internal locks, which is outside the attacker's direct control. Patches are available in FortiAnalyzer/FortiManager versions 7.6.5 and 7.4.9.

Affected products

  • Fortinet FortiAnalyzer 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2 all versions, 7.0 all versions, 6.4 all versions
  • Fortinet FortiManager 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2 all versions, 7.0 all versions, 6.4 all versions

Timeline

  • 2026-05-12: advisory: Initial publication by Fortinet
  • 2026-05-12: disclosed

References

Related threats