CVE-2025-67604
Last modified
CVE-2025-67604 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortianalyzer | >= 7.2.0, <= 7.2.12 |
| Fortinet | Fortianalyzer | >= 7.4.0, < 7.4.9 |
| Fortinet | Fortianalyzer | >= 7.6.0, < 7.6.5 |
| Fortinet | Fortimanager | >= 7.2.0, <= 7.2.12 |
| Fortinet | Fortimanager | >= 7.4.0, < 7.4.9 |
| Fortinet | Fortimanager | >= 7.6.0, < 7.6.5 |
References
- https://fortiguard.fortinet.com/psirt/FG-IR-26-137Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-67604?
How severe is CVE-2025-67604?
How do I fix CVE-2025-67604?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-67596Cross-Site Request Forgery (CSRF) vulnerability in Strategy1…4.3
- CVE-2025-67597Missing Authorization vulnerability in Shahjahan Jewel Fluen…4.3
- CVE-2025-67598Cross-Site Request Forgery (CSRF) vulnerability in PSM Plugi…4.3
- CVE-2025-67599Missing Authorization vulnerability in WebToffee WebToffee e…4.3
- CVE-2025-67601A vulnerability has been identified within Rancher Manager, …4.8
- CVE-2025-67603A Improper Authorization vulnerability in Foomuuri llows arb…5.1
- CVE-2025-67605Rejected reason: Not used
- CVE-2025-67606Rejected reason: Not used
- CVE-2025-67607Rejected reason: Not used
- CVE-2025-67608Rejected reason: Not used
- CVE-2025-67609Rejected reason: Not used
- CVE-2025-6761A vulnerability was found in Kingdee Cloud-Starry-Sky Enterp…7.3
Are you affected by CVE-2025-67604?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
