A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions may allow an authenticated attacker with read-write admin privileges to the CLI to obtain other administrators' credentials via diagnose commands.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-789 | Vendor Advisory |
Configurations
History
20 Nov 2025, 14:37
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:* | |
| First Time |
Fortinet
Fortinet fortipam |
|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-25-789 - Vendor Advisory |
18 Nov 2025, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-18 17:16
Updated : 2025-11-20 14:37
NVD link : CVE-2025-61713
Mitre link : CVE-2025-61713
CVE.ORG link : CVE-2025-61713
JSON object : View
Products Affected
fortinet
- fortipam
CWE
CWE-316
Cleartext Storage of Sensitive Information in Memory
