PT-2025-47365 · Fortinet · Fortipam
Published
2025-11-18
·
Updated
2025-11-19
·
CVE-2025-61713
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FortiPAM versions 1.0 through 1.6.0
Description
A cleartext storage of sensitive information in memory issue exists in FortiPAM. An authenticated attacker with read-write administrative privileges to the command-line interface (CLI) may be able to obtain other administrators' credentials through the use of diagnose commands. This allows for potential lateral privilege escalation within a network.
Recommendations
FortiPAM version 1.6.0 and earlier should be updated.
FortiPAM versions 1.5, 1.4, 1.3, 1.2, and 1.1 should be updated.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortipam