CVE-2025-54973

A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0

Severity
Medium 5.3
CVSS 3.1
Exploited
Not listed
EPSS
0.003
21.6th percentile
Discovered by
Not disclosed
Published
Oct 14, 2025
Assigned by fortinet

Description

A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10 and before 7.0.13 allows an attacker to attempt to win a race condition to bypass the FortiCloud SSO authorization via crafted FortiCloud SSO requests.

Weakness: CWE-362

Affected products

Vendor Product Category Matched by
Fortinet FortiAnalyzer SIEM & Log Management cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiAnalyzer

Vendor remediation

Upgrade to FortiAnalyzer version 7.6.3 or above Upgrade to FortiAnalyzer version 7.4.7 or above Upgrade to FortiAnalyzer version 7.2.11 or above Upgrade to FortiAnalyzer version 7.0.14 or above