CVE-2025-68648

HIGH

Fortinet FortiAnalyzer/FortiManager - Memory Corruption

Title source: llm
STIX 2.1

Description

A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.2 through 7.6.3, FortiManager Cloud 7.4.1 through 7.4.7, FortiManager Cloud 7.2.1 through 7.2.10, FortiManager Cloud 7.0.1 through 7.0.14 may allow an attacker to escalate its privileges via specially crafted requests.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0057
EPSS Percentile 42.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-134
Status published
Products (20)
Fortinet/FortiAnalyzer 7.0.0 - 7.0.16
fortinet/fortianalyzer 7.0.0 - 7.4.8
Fortinet/FortiAnalyzer 7.2.0 - 7.2.12
Fortinet/FortiAnalyzer 7.4.0 - 7.4.7
Fortinet/FortiAnalyzer 7.6.0 - 7.6.4
Fortinet/FortiAnalyzer Cloud 7.0.1 - 7.0.16
Fortinet/FortiAnalyzer Cloud 7.2.1 - 7.2.12
Fortinet/FortiAnalyzer Cloud 7.4.1 - 7.4.7
Fortinet/FortiAnalyzer Cloud 7.6.2
fortinet/fortianalyzer_cloud 7.0.0 - 7.4.8
... and 10 more
Published Mar 10, 2026
Tracked Since Mar 11, 2026