CVE-2025-68648: Format string vulnerability in fazsvcd
A use of externally-controlled format string vulnerability [CWE-134] in FortiAnalyzer, FortiAnalyzer Cloud, FortiManager and FortiManager Cloud fazsvcd daemon may allow a remote privileged attacker with admin profile to execute arbitrary code or commands via specially crafted requests.
Other sources
A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.2 through 7.6.3, FortiManager Cloud 7.4.1 through 7.4.7, FortiManager Cloud 7.2.1 through 7.2.10, FortiManager Cloud 7.0.1 through 7.0.14 may allow an attacker to escalate its privileges via specially crafted requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68648?
CVE-2025-68648 has been classified as a critical vulnerability due to its potential to allow remote privileged attackers to execute arbitrary code.
How do I fix CVE-2025-68648?
To mitigate CVE-2025-68648, you should upgrade FortiAnalyzer, FortiAnalyzer Cloud, FortiManager, or FortiManager Cloud to the versions 7.6.5 or 7.4.8 or higher.
Which Fortinet products are affected by CVE-2025-68648?
CVE-2025-68648 affects FortiAnalyzer, FortiAnalyzer Cloud, FortiManager, and FortiManager Cloud versions between 7.4.0 and 7.6.4.
Can I use previously released versions of Fortinet products with CVE-2025-68648?
Using previously released versions below 7.4.8 or 7.6.5 for the affected Fortinet products poses a security risk due to CVE-2025-68648.
What type of vulnerability is CVE-2025-68648?
CVE-2025-68648 is categorized as a format string vulnerability, which is a type of security weakness that can be exploited by unauthorized users.