Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xw8w-pqw7-c52c

Опубликовано: 09 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 2.7

Описание

A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least sponsor permissions to read and download device logs via accessing specific endpoints

A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least sponsor permissions to read and download device logs via accessing specific endpoints

EPSS

Процентиль: 8%
0.00031
Низкий

2.7 Low

CVSS3

Дефекты

CWE-425

Связанные уязвимости

CVSS3: 2.7
nvd
2 месяца назад

A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least sponsor permissions to read and download device logs via accessing specific endpoints

EPSS

Процентиль: 8%
0.00031
Низкий

2.7 Low

CVSS3

Дефекты

CWE-425