An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.13 and below and FortiManager version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.12 and below may allow an unauthenticated remote attacker to pollute the logs via crafted login requests.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortianalyzer | — | Upgrade FortiAnalyzer to 7.6.2Upgrade FortiAnalyzer to 7.4.6Upgrade FortiAnalyzer to 7.2.9Upgrade FortiAnalyzer to 7.0.14 | Jul 25, 2025 | Apr 8, 2025 |
| Fortinet Fortimanager | — | Upgrade FortiManager to 7.0.14Upgrade FortiManager to 7.4.6Upgrade FortiManager to 7.2.9Upgrade FortiManager to 7.6.2 | May 25, 2026 | Apr 8, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub