CVE-2025-46752
A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the enrollment code.
Severity
Medium 4.2
CVSS 3.1
Exploited
Not listed
EPSS
0.002
5.5th percentile
Discovered by
Vendor
Vendor advisory field
Published
Oct 16, 2025
Assigned by fortinet
Description
A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the enrollment code.
Weakness: CWE-532
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiDLP | Endpoint / EDR | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiDLP
Credit
Internally discovered and reported by Leslie Zhou of Fortinet Product Security team.
Vendor remediation
Upgrade to FortiDLP version 12.1.0 or above