A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | FortiAuthenticator | 8.0.2, 8.0.0, 6.6.0, 6.5.0, 6.4.0 |
Updated affected versions with new FortiOS and FortiSandbox versions and added detailed description of the vulnerability.
Added affected version 6.4.10, updated severity from CRITICAL to HIGH, and noted that no exploit is available.
Updated affected versions to include 6.5.7 and 6.6.9, added new description details, and included new tags related to IAM and IDaaS.
Updated affected versions to include 8.0.3, 6.6.9, and 6.5.7, and marked exploit availability and active exploitation as true.
Initial creation