Home

Description

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all versions, FortiADC 7.1 all versions, FortiADC 7.0 all versions, FortiADC 6.2 all versions may allow an admin with read-only permission to get the external resources password via the logs of the product

PUBLISHED Reserved 2025-08-04 | Published 2025-11-18 | Updated 2025-11-19 | Assigner fortinet




LOW: 3.9CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C

Problem types

Information disclosure

Product status

Default status
unaffected

7.4.0
affected

7.2.0 (semver)
affected

7.1.0 (semver)
affected

7.0.0 (semver)
affected

6.2.0 (semver)
affected

References

fortiguard.fortinet.com/psirt/FG-IR-25-686

cve.org (CVE-2025-54971)

nvd.nist.gov (CVE-2025-54971)

Download JSON