CVE-2024-40593
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-12-11
Last updated on: 2025-12-12
Assigner: Fortinet, Inc.
Description
Description
A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions, FortiOS 7.6.0, FortiOS 7.4.4, FortiOS 7.2.7, FortiOS 7.0.14, FortiPortal 6.0 all versions may allow an authenticated admin to retrieve a certificate's private key via the device's admin shell.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fortinet | fortianalyzer | From 6.4.0 (inc) to 7.2.6 (exc) |
| fortinet | fortianalyzer | From 7.4.0 (inc) to 7.4.3 (exc) |
| fortinet | fortimanager | From 6.4.0 (inc) to 7.2.6 (exc) |
| fortinet | fortimanager | From 7.4.0 (inc) to 7.4.3 (exc) |
| fortinet | fortios | 7.0.14 |
| fortinet | fortios | 7.2.7 |
| fortinet | fortios | 7.4.4 |
| fortinet | fortios | 7.6.0 |
| fortinet | fortiportal | From 6.0.0 (inc) to 6.0.15 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-NVD-CWE-noinfo | |
| CWE-320 | Key Management Errors |