Sensitive Information Exposure in Fortinet FortiADC Products
CVE-2025-54971

3.9LOW

Key Information:

Vendor

Fortinet

Status
Vendor
CVE Published:
18 November 2025

What is CVE-2025-54971?

A vulnerability affecting Fortinet FortiADC products allows an administrator with read-only permission to access sensitive information, specifically the passwords for external resources, through product logs. This security flaw poses a risk by enabling unauthorized actors to gain sensitive credentials, potentially leading to unauthorized access to system functionalities and data compromise.

Affected Version(s)

FortiADC 7.4.0

FortiADC 7.2.0 <= 7.2.8

FortiADC 7.1.0 <= 7.1.5

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54971 : Sensitive Information Exposure in Fortinet FortiADC Products