← Back

CVE-2024-33504

nvd nist
Published: Feb 11, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Exploitability: 3.1 / Impact: 4.0
Source: NVD

Description

A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9, 7.0 all versions, 6.4 all versions may allow an attacker with JSON API access permissions to decrypt some secrets even if the 'private-data-encryption' setting is enabled.

Affected (5)

2 products
Fortimanager
Fortimanager Cloud
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 6.4.0 to 7.2.10
From 7.4.0 to 7.4.6
From 7.6.0 to 7.6.2
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 6.4.1 to 7.2.9
From 7.4.1 to 7.4.6

References (2)

Timeline

No history available yet.