Impact
An out‑of‑bounds read flaw in Fortinet FortiAuthenticator allows a remote attacker to request a specially crafted message and read memory that lies beyond a buffer boundary. The vulnerability can expose sensitive information such as credentials, configuration data, or other private data stored in RAM. The incorrect memory access does not provide a pathway to execute code or alter system state, but it does weaken confidentiality of data stored on the device.
Affected Systems
Fortinet FortiAuthenticator devices running firmware versions 6.6.0 through 6.6.2 and every release in the 6.5.x series are vulnerable. Firmware 6.6.3 and newer, as well as any versions below 6.5, contain the fix and are not affected. Users should verify the firmware version deployed on their units and plan a correct upgrade path if necessary.
Risk and Exploitability
The CVSS score of 7 indicates a moderate to high impact on confidentiality. The EPSS score of less than 1% suggests that attacks are currently unlikely to be observed in the wild, and the vulnerability is not listed in the CISA KEV catalog. An attacker only needs network access to the FortiAuthenticator management interface; authentication is not required. If exploited, the attacker can retrieve data from the device’s memory, potentially compromising user accounts or network information. Prompt remediation is recommended despite the low exploitation probability.
OpenCVE Enrichment