vulnerability
Fortinet FortiAnalyzer: Improper Output Neutralization for Logs (CVE-2024-52962)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:N/I:P/A:N) | Apr 8, 2025 | Jul 25, 2025 | Aug 1, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Apr 8, 2025
Added
Jul 25, 2025
Modified
Aug 1, 2025
Description
An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.13 and below and FortiManager version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.12 and below may allow an unauthenticated remote attacker to pollute the logs via crafted login requests.
Solutions
fortinet-fortianalyzer-upgrade-7_0_14fortinet-fortianalyzer-upgrade-7_2_9fortinet-fortianalyzer-upgrade-7_4_6fortinet-fortianalyzer-upgrade-7_6_2
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.