Missing authentication check in OFTP service

Summary

An improper authentication vulnerability [CWE-287] in FortiAnalyzer may allow an unauthenticated attacker to obtain information pertaining to the device's health and status, or cause a denial of service via crafted OFTP requests.

Version Affected Solution
FortiAnalyzer 7.6 7.6.0 through 7.6.3 Upgrade to 7.6.4 or above
FortiAnalyzer 7.4 7.4.0 through 7.4.6 Upgrade to 7.4.7 or above
FortiAnalyzer 7.2 7.2 all versions Migrate to a fixed release
FortiAnalyzer 7.0 7.0 all versions Migrate to a fixed release
FortiAnalyzer 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Kai Ni of Burnaby Infosec team.

Timeline

2025-10-14: Initial publication