Fortinet FortiAnalyzer
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*, +1 more
- >= 7.6.0, <= 7.6.4
- >= 7.4.0, <= 7.4.8
- ~7.2
- ~7.0
- ~6.4
A vulnerability allowing denial-of-service conditions has been identified in Fortinet FortiAnalyzer and FortiManager. This issue affects multiple versions across different release branches. The vulnerability arises from a use of potentially dangerous functions in the API, which can be exploited by an authenticated attacker. By sending multiple specially crafted HTTP requests, the attacker can cause the system to hang and crash. This disruption occurs if internal locks are aligned, a condition that is not under the attacker's control.
Exploitation of this vulnerability leads to a system hang, causing crashes and disrupting normal operations.
Users can upgrade FortiAnalyzer to version 7.6.5 or 7.4.9, depending on their current version. FortiManager users should upgrade to the same respective versions. For FortiAnalyzer and FortiManager 7.2, users should migrate to a fixed release.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.