CVE-2024-40593

⚪ Do wiadomości

Błąd zarządzania kluczami w Fortinet FortiAnalyzer i FortiManager pozwala na wykradzenie klucza prywatnego.

CVSS
6.0
EPSS
0.1%
Exploit
none
Vendor
fortinet
Opis źródłowy (NVD)

A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions, FortiOS 7.6.0, FortiOS 7.4.4, FortiOS 7.2.7, FortiOS 7.0.14, FortiPortal 6.0 all versions may allow an authenticated admin to retrieve a certificate's private key via the device's admin shell.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.0
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.1%
Opublikowano (NVD)2025-12-11 15:15:46 UTC
Ostatnia modyfikacja (NVD)2026-10-02 00:10:00 UTC
Referencje