High Severity Vulnerability
This vulnerability has been rated as High severity. Immediate action is recommended.
CVE-2025-68648
HighVulnerability Description
A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.7, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.0 through 7.6.4, FortiManager Cloud 7.4.0 through 7.4.7, FortiManager Cloud 7.2 all versions, FortiManager Cloud 7.0 all versions may allow an attacker to escalate its privileges via specially crafted requests.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Known Affected Software
149 configuration(s) from 1 vendor(s)
cpe:2.3:a:fortinet:fortimanager_cloud:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.0.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.2.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.6.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.6.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.2.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.0.14:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.0.14:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.0.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.2.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.2.11:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.2.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.2.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.2.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.2.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.4.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.2.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.6.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.2.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.2.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.6.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.0.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.0.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.0.13:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.6.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.0.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.2.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.6.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.0.11:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.0.11:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.4.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.0.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.6.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.0.11:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.2.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.6.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.2.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.0.14:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.2.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.0.13:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.4.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.2.11:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.0.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.6.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.2.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.0.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.2.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.0.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.0.11:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.0.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.2.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.0.12:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.6.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.0.13:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.2.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.0.14:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.0.12:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.0.12:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.0.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.0.13:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.2.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.6.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.0.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.4.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.6.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.2.11:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.0.12:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager_cloud:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer_cloud:7.2.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:7.2.5:*:*:*:*:*:*:*
References & Resources
Severity Details
Weakness Type (CWE)
Use of Externally-Controlled Format String
- Description
- The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
- Exploit Likelihood
- High
- Typical Severity
- Medium
- Abstraction Level
- Base
Key Information
- Published Date
- March 10, 2026
External Resources
Related News Articles
Latest news and updates about CVE-2025-68648
