PT-2025-50117 · Fortinet · Fortiauthenticator

Published

2025-12-09

·

Updated

2025-12-10

·

CVE-2025-57823

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiAuthenticator versions 6.3 through 6.6.6 Fortinet FortiAuthenticator version 6.5 Fortinet FortiAuthenticator version 6.4 Fortinet FortiAuthenticator version 6.6.0 through 6.6.6
Description An authenticated attacker with sponsor permissions may be able to read and download device logs by directly requesting specific endpoints. This is due to a direct request ('forced browsing') issue.
Recommendations Fortinet FortiAuthenticator versions prior to 6.3 should be updated. Fortinet FortiAuthenticator version 6.3 should be updated. Fortinet FortiAuthenticator version 6.4 should be updated. Fortinet FortiAuthenticator version 6.5 should be updated. Fortinet FortiAuthenticator versions 6.6.0 through 6.6.6 should be updated.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-57823

Affected Products

Fortiauthenticator