CVE-2025-54973

A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0

Severity
Medium 5.3
CVSS 3.1
Exploited
Not listed
EPSS
0.003
24.6th percentile
Discovered by
Vendor
Vendor advisory field
Published
Oct 14, 2025
Assigned by fortinet

Description

A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10 and before 7.0.13 allows an attacker to attempt to win a race condition to bypass the FortiCloud SSO authorization via crafted FortiCloud SSO requests.

Weakness: CWE-362

Affected products

Vendor Product Category Matched by
Fortinet FortiAnalyzer SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiAnalyzer

Credit

Internally discovered and reported by Qi Fan of Fortinet FortiAnalyzer development team.

Vendor remediation

Upgrade to FortiAnalyzer version 7.6.3 or above Upgrade to FortiAnalyzer version 7.4.7 or above Upgrade to FortiAnalyzer version 7.2.11 or above Upgrade to FortiAnalyzer version 7.0.14 or above

Something wrong here?