Fortinet
Fortinet Fortiauthenticator: vulnerabilidades y CVE
Fortinet Fortiauthenticator tiene 24 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE24
Últimos 12 meses5
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-53379 | Alta (7.5) | 0.53% | — | 14 jul 2026 | A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially… |
| CVE-2026-44277 | Crítica (9.8) | 0.48% | — | 12 may 2026 | A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute… |
| CVE-2026-21743 | Alta (7.2) | 0.36% | — | 10 feb 2026 | A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow a… |
| CVE-2025-59923 | Baja (2.7) | 0.21% | — | 9 dic 2025 | An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an… |
| CVE-2025-57823 | Baja (2.7) | 0.23% | — | 9 dic 2025 | A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may… |
| CVE-2022-23439 | Media (6.1) | 0.45% | — | 22 ene 2025 | A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver |
| CVE-2024-23664 | Media (6.1) | 0.35% | — | 3 jun 2024 | A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via… |
| CVE-2022-22302 | Baja (3.3) | 0.29% | — | 11 jul 2023 | A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of… |
| CVE-2022-35850 | Media (6.1) | 0.49% | — | 11 abr 2023 | An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote… |
| CVE-2023-26208 | Media (5.3) | 1.8% | — | 9 mar 2023 | A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via… |
| CVE-2021-26116 | Alta (8.8) | 0.62% | — | 6 abr 2022 | An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of FortiAuthenticator before 6.3.1 may allow an authenticated attacker to execute unauthorized commands… |
| CVE-2021-36177 | Media (4.3) | 0.30% | — | 2 feb 2022 | An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated… |
| CVE-2021-43068 | Alta (8.1) | 0.58% | — | 9 dic 2021 | A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal. |
| CVE-2021-43067 | Media (6.5) | 1.1% | — | 8 dic 2021 | A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2 and below, version 6.2.1 and below, version 6.1.2 and below, version 6.0.7 to 6.0.1 allows… |
| CVE-2021-22124 | Alta (7.5) | 1.0% | — | 4 ago 2021 | An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may… |
| CVE-2021-24005 | Alta (7.5) | 0.56% | — | 6 jul 2021 | Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuration to decrypt the… |
| CVE-2019-16154 | Media (6.1) | 0.70% | — | 7 ene 2020 | An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page. |
| CVE-2018-9186 | Media (6.1) | 0.75% | — | 31 may 2018 | A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows attacker to execute unauthorized script code via inject malicious scripts… |
| CVE-2015-1459 | Media (4.3) | 2.0% | — | 3 feb 2015 | Cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the operation parameter to cert/scep/. |
| CVE-2015-1458 | Media (6.9) | 0.45% | — | 3 feb 2015 | Fortinet FortiAuthenticator 3.0.0 allows local users to bypass intended restrictions and gain privileges by creating /tmp/privexec/dbgcore_enable_shell_access and executing the "shell" command. |
| CVE-2015-1457 | Media (4.9) | 0.49% | — | 3 feb 2015 | Fortinet FortiAuthenticator 3.0.0 allows local users to read arbitrary files via the -f flag to the dig command. |
| CVE-2015-1456 | Media (4) | 1.4% | — | 3 feb 2015 | Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which allows remote administrators to obtain sensitive information by reading the log at debug/startup/. |
| CVE-2015-1455 | Alta (7.5) | 2.7% | — | 3 feb 2015 | Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) www-data for the www-data PostgreSQL user, which makes it easier for remote attackers to obtain access via unspecified… |
| CVE-2013-6990 | Alta (9) | 1.1% | — | 30 abr 2014 | FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.