cbcvebase.

Fortinet Fortiauthenticator vulnerabilities

24 known vulnerabilities affecting fortinet/fortiauthenticator.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH7MEDIUM12LOW3

Vulnerabilities

Page 2 of 2
CVE-2015-1456P4MEDIUMCVSS 4.0v3.0.02015-02-03
CVE-2015-1456 [MEDIUM] CWE-200 CVE-2015-1456: Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which al Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which allows remote administrators to obtain sensitive information by reading the log at debug/startup/.
nvd
CVE-2025-57823P4LOWCVSS 2.7≥ 6.3.0, ≤ 6.6.6≥ 6.6.0, ≤ 6.6.6+2 more2025-12-09
CVE-2025-57823 [LOW] CWE-425 CVE-2025-57823: A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6. A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least sponsor permissions to read and download device logs via accessing specific endpoints
nvd
CVE-2025-59923P4LOWCVSS 2.7≥ 6.3.0, ≤ 6.6.4≥ 6.6.0, ≤ 6.6.6+2 more2025-12-09
CVE-2025-59923 [LOW] CWE-284 CVE-2025-59923: An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAu An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least read-only admin permission to obtain the credentials of other administrators' messaging services via
nvd
CVE-2022-22302P4LOWCVSS 3.3≥ 6.0.0, ≤ 6.0.4v5.5.0+1 more2023-07-11
CVE-2022-22302 [LOW] CWE-312 CVE-2022-22302: A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4. A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allow a local unauthorized party to retrieve the Fortinet private keys used to establish secure communication with both
nvd