A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.
| Vendor | Product | Versions |
|---|---|---|
| fortinet | fortiauthenticator | 6.6.0, 6.5.0, 6.4.0, 6.3.0 |
Updated affected versions to include 6.5.1 through 6.5.7 and marked the vulnerability as actively exploited with an exploit available.
Updated affected versions to include 6.3.5, 6.4.11, and 6.5.7, and corrected exploit availability to false.
Initial creation