CVE-2025-57823
⚪ Do wiadomości
Luka w FortiAuthenticator umożliwia atakującemu dostęp do logów urządzeń.
CVSS
2.7
EPSS
0.2%
Exploit
none
Vendor
fortinet
Opis źródłowy (NVD)
A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least sponsor permissions to read and download device logs via accessing specific endpoints
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 2.7 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2025-12-09 18:15:54 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 23:10:00 UTC |
Referencje
- https://fortiguard.fortinet.com/psirt/FG-IR-25-554 ([email protected]) [Vendor Advisory]