Home

Description

A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the enrollment code.

PUBLISHED Reserved 2025-04-29 | Published 2025-10-16 | Updated 2025-10-16 | Assigner fortinet




MEDIUM: 4.2CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:P/RL:U/RC:C

Problem types

Information disclosure

Product status

Default status
unaffected

12.0.4
affected

12.0.2
affected

12.0.0
affected

11.5.1
affected

11.4.5
affected

References

fortiguard.fortinet.com/psirt/FG-IR-25-160

cve.org (CVE-2025-46752)

nvd.nist.gov (CVE-2025-46752)

Download JSON