CVE-2025-67604: DoS due to unsafe function in signal handler
A use of potentially Dangerous Function vulnerability [CWE-676] in FortiAnalyzer and FortiManager API may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67604?
CVE-2025-67604 is categorized as a denial of service vulnerability.
How do I fix CVE-2025-67604?
To address CVE-2025-67604, update FortiAnalyzer and FortiManager to versions 7.6.5 or 7.4.9 or later.
What products are affected by CVE-2025-67604?
CVE-2025-67604 affects FortiAnalyzer and FortiManager versions prior to 7.6.5 and 7.4.9 respectively.
What kind of attack can exploit CVE-2025-67604?
An authenticated attacker can exploit CVE-2025-67604 by sending multiple specially crafted HTTP requests, causing a system hang.
Is there a workaround for CVE-2025-67604?
There is no known workaround for CVE-2025-67604; the recommended action is to upgrade to the fixed versions.