Fortinet FortiMail
cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*
- >= 6.4.0, <= 6.4.4
- >= 6.2.0, <= 6.2.7
A vulnerability has been identified in Fortinet FortiMail versions 6.4.0 to 6.4.4 and 6.2.0 to 6.2.7. This vulnerability arises from the use of a cryptographically weak pseudo-random number generator in the authenticator of the Identity Based Encryption service. It may allow an unauthenticated attacker to infer parts of users' authentication tokens and reset their credentials.
Exploitation of this vulnerability could lead to unauthorized inference of authentication token parts, allowing for credential resets.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.