Executive brief
FortiAnalyzer is a centralized security log and analytics appliance used by enterprises to monitor network traffic and security events. A flaw in its SNMP (network monitoring protocol) service allows authenticated users to crash the service through specially crafted requests, causing temporary unavailability of security monitoring and log collection capabilities.
Technical details
A use-of-uninitialized-variable vulnerability (CWE-457) exists in the FortiAnalyzer SNMP daemon that processes GETBULK requests. The vulnerability requires authentication and is reachable over the network via SNMP protocol. A remote authenticated attacker can trigger the uninitialized variable condition through malformed GETBULK requests, causing the SNMP daemon to crash and resulting in denial of service. The vulnerability affects FortiAnalyzer versions 7.6.3 through 7.6.6; patches are available in version 7.6.7 and later.
Affected products
- Fortinet FortiAnalyzer 7.6.3 through 7.6.6
Timeline
- 2026-09-08: disclosed