CVE-2025-54973
A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0
Description
A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10 and before 7.0.13 allows an attacker to attempt to win a race condition to bypass the FortiCloud SSO authorization via crafted FortiCloud SSO requests.
Weakness: CWE-362
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiAnalyzer | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiAnalyzer
Credit
Internally discovered and reported by Qi Fan of Fortinet FortiAnalyzer development team.
Vendor remediation
Upgrade to FortiAnalyzer version 7.6.3 or above Upgrade to FortiAnalyzer version 7.4.7 or above Upgrade to FortiAnalyzer version 7.2.11 or above Upgrade to FortiAnalyzer version 7.0.14 or above