CVE-2024-46665: Fortinet FortiOS
Low severity, CVSS 3.7. EPSS: 0.5% chance of exploitation in the next 30 days.
An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests.
Affected products
- Fortinet FortiOS: from 7.4.0, before 7.4.5 (fixed in 7.4.5); version 7.6.0 only
Published 2025-01-14. Last modified 2026-06-17.