Description
A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.
Published: 2026-07-14
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds read flaw in Fortinet FortiAuthenticator allows a remote attacker to request a specially crafted message and read memory that lies beyond a buffer boundary. The vulnerability can expose sensitive information such as credentials, configuration data, or other private data stored in RAM. The incorrect memory access does not provide a pathway to execute code or alter system state, but it does weaken confidentiality of data stored on the device.

Affected Systems

Fortinet FortiAuthenticator devices running firmware versions 6.6.0 through 6.6.2 and every release in the 6.5.x series are vulnerable. Firmware 6.6.3 and newer, as well as any versions below 6.5, contain the fix and are not affected. Users should verify the firmware version deployed on their units and plan a correct upgrade path if necessary.

Risk and Exploitability

The CVSS score of 7 indicates a moderate to high impact on confidentiality. The EPSS score of less than 1% suggests that attacks are currently unlikely to be observed in the wild, and the vulnerability is not listed in the CISA KEV catalog. An attacker only needs network access to the FortiAuthenticator management interface; authentication is not required. If exploited, the attacker can retrieve data from the device’s memory, potentially compromising user accounts or network information. Prompt remediation is recommended despite the low exploitation probability.

Generated by OpenCVE AI on July 31, 2026 at 10:12 UTC.

Remediation

Vendor Solution

Upgrade to FortiAuthenticator version 6.6.3 or above


OpenCVE Recommended Actions

  • Upgrade FortiAuthenticator to version 6.6.3 or later
  • Limit external connectivity to the FortiAuthenticator management interface by placing it behind a firewall or VPN and restricting allowed IP ranges
  • Monitor FortiAuthenticator logs for abnormal request patterns or repeated failed access attempts that may indicate probing for the vulnerability

Generated by OpenCVE AI on July 31, 2026 at 10:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read Enabling Remote Data Exposure in FortiAuthenticator

Wed, 29 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in FortiAuthenticator Allows Sensitive Data Disclosure

Thu, 23 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in FortiAuthenticator Allows Sensitive Data Disclosure

Fri, 17 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read Leads to Remote Data Exposure in FortiAuthenticator

Thu, 16 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read Leads to Remote Data Exposure in FortiAuthenticator

Tue, 14 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.
First Time appeared Fortinet
Fortinet fortiauthenticator
Weaknesses CWE-125
CPEs cpe:2.3:a:fortinet:fortiauthenticator:6.3.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.3.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.3.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.3.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.3.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.3.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.11:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.4.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.5.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiauthenticator:6.6.2:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortiauthenticator
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:F/RL:O/RC:C'}


Subscriptions

Fortinet Fortiauthenticator
cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-07-22T13:57:33.288Z

Reserved: 2025-06-27T15:44:12.816Z

Link: CVE-2025-53379

cve-icon Vulnrichment

Updated: 2026-07-14T15:56:02.315Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:15:06Z

Weaknesses