CVE-2025-57823

Source
https://cve.org/CVERecord?id=CVE-2025-57823
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57823.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-57823
Published
2025-12-09T18:15:54.480Z
Modified
2026-03-13T03:35:11.336439Z
Severity
  • 2.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least sponsor permissions to read and download device logs via accessing specific endpoints

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "6.3.0"
            },
            {
                "last_affected": "6.6.6"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57823.json"