CVE-2023-25610: Fortinet Fortianalyzer

Critical severity, CVSS 9.8. EPSS: 18.3% chance of exploitation in the next 30 days.

A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

Affected products

  • Fortinet Fortianalyzer: from 6.0.0, before 6.0.12 (fixed in 6.0.12); from 6.2.0, before 6.2.11 (fixed in 6.2.11); from 6.4.0, before 6.4.12 (fixed in 6.4.12); from 7.0.0, before 7.0.5 (fixed in 7.0.5); version 7.2.0 only
  • Fortinet FortiManager: from 6.0.0, before 6.0.12 (fixed in 6.0.12); from 6.2.0, before 6.2.11 (fixed in 6.2.11); from 6.4.0, before 6.4.12 (fixed in 6.4.12); from 7.0.0, before 7.0.5 (fixed in 7.0.5); version 7.2.0 only
  • Fortinet FortiOS: from 5.0.0, before 6.2.13 (fixed in 6.2.13); from 6.4.0, before 6.4.12 (fixed in 6.4.12); from 7.0.0, before 7.0.10 (fixed in 7.0.10); from 7.2.0, before 7.2.4 (fixed in 7.2.4)
  • Fortinet FortiOS-6k7k: from 6.0.4, before 6.2.13 (fixed in 6.2.13); from 6.4.2, before 6.4.12 (fixed in 6.4.12); version 7.0.5 only
  • Fortinet FortiProxy: from 1.1.0, before 7.0.9 (fixed in 7.0.9); from 7.2.0, before 7.2.3 (fixed in 7.2.3)
  • Fortinet Fortiswitch: from 7.0.0, before 7.0.7 (fixed in 7.0.7); from 7.2.0, before 7.2.4 (fixed in 7.2.4)
  • Fortinet Fortiswitchmanager: from 7.0.0, before 7.0.2 (fixed in 7.0.2); from 7.2.0, before 7.2.2 (fixed in 7.2.2)
  • Fortinet FortiWeb: from 6.1.0, before 6.1.4 (fixed in 6.1.4); from 6.2.0, before 6.2.8 (fixed in 6.2.8); from 6.3.0, before 6.3.23 (fixed in 6.3.23); from 6.4.0, before 6.4.3 (fixed in 6.4.3); from 7.0.0, before 7.0.7 (fixed in 7.0.7); from 7.2.0, before 7.2.2 (fixed in 7.2.2)

Published 2025-03-24. Last modified 2026-06-17.