CVE-2025-54971
An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all versions, FortiADC 7.1 all versions, FortiADC 7.0 all versions, FortiADC 6.2 al
Severity
Low 3.9
CVSS 3.1
Exploited
Not listed
EPSS
0.002
14.3th percentile
Discovered by
Vendor
Vendor advisory field
Published
Nov 18, 2025
Assigned by fortinet
Description
An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all versions, FortiADC 7.1 all versions, FortiADC 7.0 all versions, FortiADC 6.2 all versions may allow an admin with read-only permission to get the external resources password via the logs of the product
Weakness: CWE-200
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiADC | Web & Application Security | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiADC
Credit
Discovered by Xiao Liu of Fortinet
Vendor remediation
Upgrade to FortiADC version 7.6.0 or above Upgrade to FortiADC version 7.4.3 or above