vulnerability

Fortinet FortiAnalyzer: Improper Output Neutralization for Logs (CVE-2024-52962)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Apr 8, 2025
Added
Jul 25, 2025
Modified
Aug 1, 2025

Description

An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.13 and below and FortiManager version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.12 and below may allow an unauthenticated remote attacker to pollute the logs via crafted login requests.

Solutions

fortinet-fortianalyzer-upgrade-7_0_14fortinet-fortianalyzer-upgrade-7_2_9fortinet-fortianalyzer-upgrade-7_4_6fortinet-fortianalyzer-upgrade-7_6_2
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.