Known vulnerabilities in FortiAnalyzer-BigData

Software CPE: cpe:2.3:a:fortinet:fortianalyzer_bigdata:*:*:*:*:*:*:*:*
Total vulnerabilities: 14
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting FortiAnalyzer-BigData FortiAnalyzer-BigData is affected by 14 known vulnerabilities: 1 high, 1 medium, 12 low Critical High Medium Low

Vulnerabilities (14)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU123726 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-49784
CWE-89 Low
No
No
7.4.5, 7.6.1 10.03.2026 SB2026031088
#VU107312 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-40584
CWE-78 Low
No
No
7.2.8, 7.4.1 09.04.2025 SB2025040977
#VU105614 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-33501
CWE-89 Low
No
No
7.2.8, 7.4.1 11.03.2025 SB20250311116
#VU105613 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-32123
CWE-78 Low
No
No
7.2.8, 7.4.2 11.03.2025 SB20250311115
#VU100783 - Stack-based buffer overflow
CVE-2024-31496
CWE-121 Low
No
No
7.2.8, 7.4.1 21.11.2024 SB2024112169
SB2024112170
#VU100782 - Client-Side Enforcement of Server-Side Security
CVE-2024-23666
CWE-602 Medium
Available
No
7.2.7, 7.4.1 21.11.2024 SB2024112167
SB2024112168
#VU100460 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-35274
CWE-22 Low
No
No
7.4.1 14.11.2024 SB2024111414
SB2024111415
#VU100455 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-32118
CWE-78 Low
No
No
7.2.8, 7.4.1 14.11.2024 SB2024111412
SB2024111413
#VU100453 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-32117
CWE-22 Low
No
No
7.2.8, 7.4.1 14.11.2024 SB2024111409
SB2024111410
#VU100452 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-32116
CWE-22 Low
No
No
7.2.8, 7.4.1 14.11.2024 SB2024111404
SB2024111405
#VU100450 - Improper Access Control
CVE-2023-44255
CWE-284 Low
No
No
7.2.6 14.11.2024 SB2024111401
SB2024111402
#VU97007 - Improper Access Control
CVE-2023-44254
CWE-284 Low
No
No
7.2.6, 7.4.0 10.09.2024 SB2024091087
#VU93513 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-6387
CWE-362 High
Available
No
7.4.1 01.07.2024 SB2024070144
SB2024070145
SB2024070152
and 89 more
#VU87527 - Use of Externally-Controlled Format String
CVE-2023-41842
CWE-134 Low
No
No
7.2.6, 7.4.0 14.03.2024 SB2024031434