CVE-2025-68482

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
10/03/2026
Last modified:
12/03/2026

Description

A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to view confidential information via a man in the middle [MiTM] attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 6.4.0 (including) 7.4.9 (excluding)
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* 7.6.0 (including) 7.6.5 (excluding)
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* 6.4.0 (including) 7.4.9 (excluding)
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:* 7.6.0 (including) 7.6.5 (excluding)


References to Advisories, Solutions, and Tools