FortiAnalyzer 6.2
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in the FIPS 140-2 Compliant Operation Section of the Security Policy with the entropy token installed as indicated in the Security Policy. Authentication at level 3 is only applicable when identity-based authentication is enforced for the User role. No assurance of the minimum strength of generated keys
Certificate
| Certificate number | 4361 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 1 |
| Module type | Firmware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Fortinet, Inc. · website |
| Firmware versions | FortiAnalyzer v6.2, build9599 |
Module description
The FortiAnalyzer family of logging, analyzing, and reporting appliances securely aggregate log data from Fortinet devices and other syslog-compatible devices. Using a comprehensive suite of customizable reports, users can filter and review records, including traffic, event, virus, attack, Web content, and email data.
Security level exceptions
- Roles, Services, and Authentication: Level 3
- Design Assurance: Level 2
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | A1062, C1908, C2013 |
| CVL | C2013 |
| DRBG | C1985 |
| ECDSA | A1062 |
| HMAC | C2013 |
| KAS | |
| KAS-SSC | A1062 |
| KTS | |
| KTS | |
| RSA | A1062, C2013 |
| SHS | C2013 |
Tested configurations
- FortiAnalyzer-3500G with Intel® Xeon® Gold 5118 processor
Validation history
| Date | Type | Lab |
|---|---|---|
| 2022-11-09 | Initial | Lightship Security, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2022-11-09
Known CVEs in this module family (heuristic match)
Name-based association with the module's product family, not a statement about the validated boundary. See methodology.
| CVE | CVSS | Severity |
|---|---|---|
| CVE-2021-32603 | 8.8 | HIGH |
| CVE-2022-39950 | 8 | HIGH |
| CVE-2019-17657 | 7.5 | HIGH |
| CVE-2020-9289 | 7.5 | HIGH |
| CVE-2021-24022 | 6.7 | MEDIUM |
| CVE-2021-42757 | 6.7 | MEDIUM |
| CVE-2021-43072 | 6.7 | MEDIUM |
| CVE-2024-33502 | 6.5 | MEDIUM |
| CVE-2020-12815 | 5.4 | MEDIUM |
| CVE-2020-6640 | 5.4 | MEDIUM |
| CVE-2021-32597 | 4.6 | MEDIUM |
| CVE-2021-24021 | 4.3 | MEDIUM |
| CVE-2021-32587 | 4.3 | MEDIUM |
| CVE-2021-32598 | 4.3 | MEDIUM |
| CVE-2023-36638 | 4.3 | MEDIUM |
| CVE-2021-36170 | 3.2 | LOW |