Home

Description

A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions may allow an authenticated attacker with read-write admin privileges to the CLI to obtain other administrators' credentials via diagnose commands.

PUBLISHED Reserved 2025-09-30 | Published 2025-11-18 | Updated 2025-11-18 | Assigner fortinet




LOW: 3.8CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C

Problem types

Information disclosure

Product status

Default status
unaffected

1.6.0
affected

1.5.0 (semver)
affected

1.4.0 (semver)
affected

1.3.0 (semver)
affected

1.2.0
affected

1.1.0 (semver)
affected

1.0.0 (semver)
affected

References

fortiguard.fortinet.com/psirt/FG-IR-25-789

cve.org (CVE-2025-61713)

nvd.nist.gov (CVE-2025-61713)

Download JSON