Fortinet FortiManager
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*, +1 more
- >= 7.2.3, <= 7.2.3
- 7.4.0
- >= 7.0.8, <= 7.0.8
- >= 6.4.12, <= 6.4.12
- >= 6.2.11, <= 6.2.11
A vulnerability allowing the insertion of sensitive information into log files has been identified in Fortinet FortiManager and FortiAnalyzer. This issue affects FortiManager versions 7.4.0, 7.2.3 and below, 7.0.8 and below, 6.4.12 and below, and 6.2.11 and below, as well as FortiAnalyzer versions 7.4.0, 7.2.3 and below, 7.0.8 and below, 6.4.12 and below, and 6.2.11 and below. The vulnerability may allow any low-privileged user with access to the event log section to retrieve logged certificate private keys and encrypted passwords from the system log.
Exploitation of this vulnerability could lead to unauthorized access to certificate private keys and encrypted passwords, allowing for potential further exploitation or unauthorized actions within the affected system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.