CVE-2024-40593

A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions, FortiOS 7.6.0, FortiOS 7.4.4, FortiOS 7.2.7, FortiOS 7.0.14, FortiPortal 6.0 all versions may allow an authenticated admin to retrieve a certificate's private key via the device's admin shell.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fortinet:fortios:7.0.14:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.2.7:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.4.4:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*

History

12 Dec 2025, 18:28

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.2.7:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.4.4:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.0.14:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*
References () https://fortiguard.fortinet.com/psirt/FG-IR-24-133 - () https://fortiguard.fortinet.com/psirt/FG-IR-24-133 - Vendor Advisory
First Time Fortinet
Fortinet fortianalyzer
Fortinet fortiportal
Fortinet fortimanager
Fortinet fortios

11 Dec 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-11 15:15

Updated : 2025-12-12 18:28


NVD link : CVE-2024-40593

Mitre link : CVE-2024-40593

CVE.ORG link : CVE-2024-40593


JSON object : View

Products Affected

fortinet

  • fortiportal
  • fortimanager
  • fortianalyzer
  • fortios
CWE
CWE-320

Key Management Errors

NVD-CWE-noinfo