CVE-2024-46665: Fortinet FortiOS

Low severity, CVSS 3.7. EPSS: 0.5% chance of exploitation in the next 30 days.

An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests.

Affected products

  • Fortinet FortiOS: from 7.4.0, before 7.4.5 (fixed in 7.4.5); version 7.6.0 only

Published 2025-01-14. Last modified 2026-06-17.