Skip to main content

Vendor/product archive

fortinet / fortiauthenticator CVEs

Beta · best-effort

24 CVEs tagged to fortinet / fortiauthenticator2 Critical, 5 High, 14 Medium, 3 Low, 0 Unrated.

CVE-2025-53379

Published Jul 14, 2026

A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44277

Published May 12, 2026

A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-21743

Published Feb 10, 2026

A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthentica…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59923

Published Dec 9, 2025

An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthent…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-57823

Published Dec 9, 2025

A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, Fo…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-23439

Published Jan 22, 2025

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` heade…

CVSS 4.7 · Medium

CVE-2024-23664

Published Jun 3, 2024

A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to re…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-35850

Published Apr 11, 2023

An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26208

Published Mar 9, 2023

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to pa…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-26116

Published Apr 6, 2022

An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of FortiAuthenticator before 6.3.1 may allow an authenticated at…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36177

Published Feb 2, 2022

An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA managemen…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43068

Published Dec 9, 2021

A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43067

Published Dec 8, 2021

A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2 and below, version 6.2.1 and below, version 6.1.2 and belo…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24005

Published Jul 6, 2021

Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16154

Published Jan 7, 2020

An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS)…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9186

Published May 31, 2018

A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows attacker to execute unauthorized…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1459

Published Feb 3, 2015

Cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the operation parameter to cert/sc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1458

Published Feb 3, 2015

Fortinet FortiAuthenticator 3.0.0 allows local users to bypass intended restrictions and gain privileges by creating /tmp/privexec/dbgcore_enable_shell_access and executing the "s…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1456

Published Feb 3, 2015

Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which allows remote administrators to obtain sensitive information by reading the log a…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1455

Published Feb 3, 2015

Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) www-data for the www-data PostgreSQL user, which makes it easier for remote att…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6990

Published Apr 30, 2014

FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1