CVE-2024-40593: Private key readable by admin
A key management error vulnerability [CWE-320] in FortiManager, FortiAnalyzer and FortiPortal may allow an authenticated admin to retrieve a certificate's private key via the device's admin shell.
Other sources
A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions, FortiOS 7.6.0, FortiOS 7.4.4, FortiOS 7.2.7, FortiOS 7.0.14, FortiPortal 6.0 all versions may allow an authenticated admin to retrieve a certificate's private key via the device's admin shell.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40593?
CVE-2024-40593 has been classified as a critical severity vulnerability due to its potential impact on key management.
How do I fix CVE-2024-40593?
To mitigate CVE-2024-40593, upgrade FortiManager and FortiAnalyzer to version 7.4.3 or later, or 7.2.6 or later, and also ensure FortiOS is updated to the recommended versions.
Which Fortinet products are affected by CVE-2024-40593?
CVE-2024-40593 affects FortiManager, FortiAnalyzer, and FortiPortal versions prior to the specified remedial versions.
Can authenticated users exploit CVE-2024-40593?
Yes, authenticated admin users can exploit CVE-2024-40593 to retrieve a certificate's private key from the device.
Is there a workaround for CVE-2024-40593?
There is no effective workaround for CVE-2024-40593; updating to the latest versions is the recommended mitigation.