CVE-2025-61713

A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2

Severity
Low 3.8
CVSS 3.1
Exploited
Not listed
EPSS
0.001
1.5th percentile
Discovered by
Not disclosed
Published
Nov 18, 2025
Assigned by fortinet

Description

A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions may allow an authenticated attacker with read-write admin privileges to the CLI to obtain other administrators' credentials via diagnose commands.

Weakness: CWE-316

Affected products

Vendor Product Category Matched by
Fortinet FortiPAM Identity / IAM / MFA cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiPAM

Vendor remediation

Upgrade to FortiPAM version 1.7.0 or above Upgrade to FortiPAM version 1.6.1 or above