A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least sponsor permissions to read and download device logs via accessing specific endpoints
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-554 |
|
History
Tue, 09 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fortinet:fortiauthenticator:*:*:*:*:*:*:*:* |
Tue, 09 Dec 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least sponsor permissions to read and download device logs via accessing specific endpoints | |
| First Time appeared |
Fortinet
Fortinet fortiauthenticator |
|
| Weaknesses | CWE-425 | |
| CPEs | cpe:2.3:a:fortinet:fortiauthenticator:6.3.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.3.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.3.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.3.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.3.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.4.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.4.10:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.4.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.4.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.4.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.4.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.4.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.4.6:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.4.7:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.4.8:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.4.9:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.5.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.5.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.5.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.5.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.5.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.5.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.5.6:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.6.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.6.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.6.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.6.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.6.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.6.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiauthenticator:6.6.6:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet
Fortinet fortiauthenticator |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published: 2025-12-09T17:18:45.986Z
Updated: 2025-12-09T20:43:26.934Z
Reserved: 2025-08-20T16:29:11.184Z
Link: CVE-2025-57823
Updated: 2025-12-09T20:21:08.906Z
Status : Analyzed
Published: 2025-12-09T18:15:54.480
Modified: 2025-12-09T19:45:32.077
Link: CVE-2025-57823
No data.