A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions, FortiOS 7.6.0, FortiOS 7.4.4, FortiOS 7.2.7, FortiOS 7.0.14, FortiPortal 6.0 all versions may allow an authenticated admin to retrieve a certificate's private key via the device's admin shell.
CVSS Details
- CVSS 3.1 Base Score: 6
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortianalyzer | — | Upgrade FortiAnalyzer to 7.2.6Upgrade FortiAnalyzer to 7.4.3Upgrade to the latest version of FortiAnalyzer | Apr 7, 2026 | Dec 9, 2025 |
| Fortinet Fortimanager | — | Upgrade to the latest version of FortiManagerUpgrade FortiManager to 7.2.6Upgrade FortiManager to 7.4.3 | May 25, 2026 | Dec 9, 2025 |
| Fortios | — | Upgrade FortiOS to 7.4.5Upgrade FortiOS to 7.0.15Upgrade FortiOS to 7.2.8Upgrade FortiOS to 7.6.1 | May 28, 2026 | Dec 9, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub