CVE-2025-61713

A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2

Severity
Low 3.8
CVSS 3.1
Exploited
Not listed
EPSS
0.001
1.4th percentile
Discovered by
Vendor
Vendor advisory field
Published
Nov 18, 2025
Assigned by fortinet

Description

A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions may allow an authenticated attacker with read-write admin privileges to the CLI to obtain other administrators' credentials via diagnose commands.

Weakness: CWE-316

Affected products

Vendor Product Category Matched by
Fortinet FortiPAM Identity / IAM / MFA cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiPAM

Credit

Internally discovered and reported by Deborah Geisau of Fortinet Support team and Josh Wang from Fortinet Development team.

Vendor remediation

Upgrade to FortiPAM version 1.7.0 or above Upgrade to FortiPAM version 1.6.1 or above

Something wrong here?