{"id":"CVE-2025-54973","title":"A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10 and before 7.0.13 allo…","summary":"A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10 and before 7.0.13 allo…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N","cwe":["CWE-362"],"vendor":"fortinet","product":"fortianalyzer","affected":["fortianalyzer >= 7.0.9, < 7.0.14","fortianalyzer >= 7.2.0, < 7.2.11","fortianalyzer >= 7.4.0, < 7.4.7","fortianalyzer >= 7.6.0, < 7.6.3"],"patched":["fortianalyzer 7.6.3"],"published":"2025-10-14","updated":"2026-10-08","sourceUpdated":"2026-10-08T11:10:00.250","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-54973","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-25-198","label":"psirt@fortinet.com"}],"tags":["nvd"],"epss":0.00315,"epssPercentile":0.2239,"ingestedAt":"2026-10-08T11:31:27.389Z","slug":"CVE-2025-54973","body":"## Overview\n\nA concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10 and before 7.0.13 allows an attacker to attempt to win a race condition to bypass the FortiCloud SSO authorization via crafted FortiCloud SSO requests.\n\n## Affected\n\n- `fortianalyzer >= 7.0.9, < 7.0.14`\n- `fortianalyzer >= 7.2.0, < 7.2.11`\n- `fortianalyzer >= 7.4.0, < 7.4.7`\n- `fortianalyzer >= 7.6.0, < 7.6.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `fortianalyzer 7.6.3`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}