Sensitive Information Exposure in Fortinet Products
CVE-2024-47570

6.3MEDIUM

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
9 December 2025

What is CVE-2024-47570?

A vulnerability present in Fortinet's FortiOS, FortiProxy, FortiPAM, and FortiSRA platforms permits read-only administrators to expose sensitive API tokens of other administrators. This occurs through the observation of REST API logs when REST API logging is enabled, which is not a default setting. The vulnerable versions include FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, and various versions of FortiProxy and FortiPAM. Organizations should assess their configurations to mitigate potential risks related to this vulnerability.

Affected Version(s)

FortiOS 7.4.0 <= 7.4.3

FortiOS 7.2.0 <= 7.2.7

FortiOS 7.0.4 <= 7.0.18

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-47570 : Sensitive Information Exposure in Fortinet Products