CVE-2025-53379 – FortiAuthenticator
CVSS 7.5
IMPORTANT
High with EoP or RCE – Expedited Deployment
“A single crafted request should never expose sensitive information from a trusted authentication system.”
Fortinet has released an update for FortiAuthenticator to address CVE-2025-53379, a high-severity out-of-bounds read vulnerability affecting FortiAuthenticator 6.6.0 through 6.6.2 and all versions of the 6.5 release. The flaw could allow a remote, unauthenticated attacker to retrieve sensitive information by sending a specially crafted request. The vulnerability is associated with CWE-125 (Out-of-bounds Read).
The CVSS score is 7.0, which is High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with this vulnerability.
Key Details
- Affected Product
- Fortinet Fortiauthenticator
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-125
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.