CVE-2025-68648

HIGH

Fortinet FortiAnalyzer/FortiManager - Memory Corruption

Title source: llm
STIX 2.1

Description

A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.7, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.0 through 7.6.4, FortiManager Cloud 7.4.0 through 7.4.7, FortiManager Cloud 7.2 all versions, FortiManager Cloud 7.0 all versions may allow an attacker to escalate its privileges via specially crafted requests.

Scores

CVSS v3 7.2
EPSS 0.0008
EPSS Percentile 23.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-134
Status published
Products (4)
fortinet/fortianalyzer 7.0.0 - 7.4.8
fortinet/fortianalyzer_cloud 7.0.0 - 7.4.8
fortinet/fortimanager 7.0.0 - 7.4.8
fortinet/fortimanager_cloud 7.0.0 - 7.4.8
Published Mar 10, 2026
Tracked Since Mar 11, 2026