Sensitive Information Exposure in Fortinet Products
CVE-2024-47570
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2024-47570?
A vulnerability present in Fortinet's FortiOS, FortiProxy, FortiPAM, and FortiSRA platforms permits read-only administrators to expose sensitive API tokens of other administrators. This occurs through the observation of REST API logs when REST API logging is enabled, which is not a default setting. The vulnerable versions include FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, and various versions of FortiProxy and FortiPAM. Organizations should assess their configurations to mitigate potential risks related to this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FortiOS 7.4.0 <= 7.4.3
FortiOS 7.2.0 <= 7.2.7
FortiOS 7.0.4 <= 7.0.18
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved