Sensitive Information Exposure in Fortinet Products
CVE-2024-47570
6.3MEDIUM
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2024-47570?
A vulnerability present in Fortinet's FortiOS, FortiProxy, FortiPAM, and FortiSRA platforms permits read-only administrators to expose sensitive API tokens of other administrators. This occurs through the observation of REST API logs when REST API logging is enabled, which is not a default setting. The vulnerable versions include FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, and various versions of FortiProxy and FortiPAM. Organizations should assess their configurations to mitigate potential risks related to this vulnerability.
Affected Version(s)
FortiOS 7.4.0 <= 7.4.3
FortiOS 7.2.0 <= 7.2.7
FortiOS 7.0.4 <= 7.0.18