← Back

CVE-2024-47570

nvd nist
Published: Dec 9, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.6
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.7 / Impact: 5.9
Source: NVD

Description

An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; FortiProxy 7.4.0 through 7.4.3, 7.2.0 through 7.2.11; FortiPAM 1.4 all versions, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiSRA 1.4 all versions may allow a read-only administrator to retrieve API tokens of other administrators via observing REST API logs, if REST API logging is enabled (non-default configuration).

Affected (8)

5 products
Fortios
Fortipam
Fortiproxy
Fortisase
Fortisra
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 7.0.4 to 7.0.17
From 7.2.0 to 7.2.8
From 7.4.0 to 7.4.4
From 1.0.0 to 1.4.3
Fortinet
From 7.2.0 to 7.2.12
From 7.4.0 to 7.4.4
Version 24.1.37
From 1.4.0 to 1.4.3

References (1)

Source: psirt@fortinet.com
Vendor Advisory

Timeline

No history available yet.