Fortinet FortiAnalyzer Improper Authentication Vulnerability in OFTP Service Allowing Information Disclosure and Denial-of-Service

Vulnerability

A vulnerability allowing improper authentication has been identified in Fortinet FortiAnalyzer versions 7.6.0 through 7.6.3 and prior to 7.4.6. This vulnerability allows an unauthenticated attacker to access information related to the device's health and status or to cause a denial-of-service condition by sending crafted OFTP requests.

Impact

Exploitation of this vulnerability could lead to unauthorized access to device health and status information or cause a denial-of-service condition on the affected device.

Remediation

Users of Fortinet FortiAnalyzer should upgrade to version 7.6.4 or above if they are using FortiAnalyzer 7.6, or to version 7.4.7 or above if they are using FortiAnalyzer 7.4. For those on FortiAnalyzer 7.2, 7.0, or 6.4, migration to a fixed release is recommended.

Added: Oct 14, 2025, 4:25 PM
Updated: Oct 14, 2025, 11:05 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
3.1
exploitability
7.4
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.