FortiMail - Insecure PRNG in password and token generation scheme of IBE authentication
A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of FortiMail Identity Based Encryption service may allow an unauthenticated attacker to infer parts of users authentication tokens and reset their credentials.
FortiMail 6.4.4 and below.
FortiMail 6.2.6 and below.
Upgrade to FortiMail 7.0.0.
Upgrade to FortiMail 6.4.5.