CVE-2025-68482

A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to view confidential information via a man in the middle [MiTM] attack.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*

History

12 Mar 2026, 20:13

Type Values Removed Values Added
First Time Fortinet fortimanager
Fortinet
Fortinet fortianalyzer
Summary
  • (es) Una vulnerabilidad de validación de certificado incorrecta en Fortinet FortiAnalyzer 7.6.0 hasta 7.6.4, FortiAnalyzer 7.4.0 hasta 7.4.8, FortiAnalyzer 7.2 todas las versiones, FortiAnalyzer 7.0 todas las versiones, FortiAnalyzer 6.4 todas las versiones, FortiManager 7.6.0 hasta 7.6.4, FortiManager 7.4.0 hasta 7.4.8, FortiManager 7.2 todas las versiones, FortiManager 7.0 todas las versiones, FortiManager 6.4 todas las versiones podría permitir a un atacante remoto no autenticado ver información confidencial a través de un ataque de intermediario [MitM].
References () https://fortiguard.fortinet.com/psirt/FG-IR-26-078 - () https://fortiguard.fortinet.com/psirt/FG-IR-26-078 - Vendor Advisory
CPE cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*

10 Mar 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 18:17

Updated : 2026-03-12 20:13


NVD link : CVE-2025-68482

Mitre link : CVE-2025-68482

CVE.ORG link : CVE-2025-68482


JSON object : View

Products Affected

fortinet

  • fortimanager
  • fortianalyzer
CWE
CWE-295

Improper Certificate Validation