CVE-2025-53845: Missing authentication check in OFTP service
An improper authentication vulnerability [CWE-287] in FortiAnalyzer may allow an unauthenticated attacker to obtain information pertaining to the device's health and status, or cause a denial of service via crafted OFTP requests.
Other sources
An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated attacker to obtain information pertaining to the device's health and status, or cause a denial of service via crafted OFTP requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53845?
CVE-2025-53845 is classified as a high severity vulnerability due to its potential to allow unauthenticated access to device information and denial of service.
How do I fix CVE-2025-53845?
To remediate CVE-2025-53845, upgrade FortiAnalyzer to version 7.6.4 or 7.4.7 as applicable.
Which versions of FortiAnalyzer are affected by CVE-2025-53845?
CVE-2025-53845 affects FortiAnalyzer versions from 6.4.0 up to but not including 7.6.4 and 7.4.6.
Can CVE-2025-53845 allow data leakage?
Yes, CVE-2025-53845 can allow an unauthenticated attacker to access device health and status information.
What is the nature of the attack vector for CVE-2025-53845?
The attack vector for CVE-2025-53845 involves crafted OFTP requests targeting the FortiAnalyzer.