VDB

GCVE-110-NCSC-2026-355

GCVE-110-NCSC-2026-355
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published September 9, 2026
A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer versions 7.6.3 through 7.6.6, specifically in the SNMP daemon, may allow a remote authenticated user to cause a denial of service via SNMP GETBULK requests.

Weaknesses (CWE)

CWE-457Use of Uninitialized VariableCWE-476NULL Pointer DereferenceCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-297Improper Validation of Certificate with Host MismatchCWE-283Unverified OwnershipCWE-601URL Redirection to Untrusted Site ('Open Redirect')

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C

Affected Products

VendorProductVersionsPlatforms
Fortinetvers:unknown/*
fortinetvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

562 records in the GCVE database · Updated September 9, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›