PT-2025-50607 · Fortinet · Fortianalyzer+3

Published

2025-12-09

·

Updated

2025-12-11

·

CVE-2024-40593

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiAnalyzer versions 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.5, 7.4.0 through 7.4.2 Fortinet FortiManager versions 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.5, 7.4.0 through 7.4.2 Fortinet FortiOS versions 7.0.14, 7.2.7, 7.4.4, 7.6.0 Fortinet FortiPortal versions 6.0 all versions
Description A key management issue exists that may allow an authenticated administrator to obtain a certificate's private key through the device's admin shell.
Recommendations Fortinet FortiAnalyzer versions 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.5, 7.4.0 through 7.4.2: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Fortinet FortiManager versions 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.5, 7.4.0 through 7.4.2: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Fortinet FortiOS versions 7.0.14, 7.2.7, 7.4.4, 7.6.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Fortinet FortiPortal versions 6.0 all versions: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2026-00833
CVE-2024-40593

Affected Products

Fortianalyzer
Fortimanager
Fortios
Fortiportal