CVE-2025-46777: Low severity fortinet fortiportal vulnerability
A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.9 may allow an authenticated attacker with at least read-only admin permissions to view encrypted secrets via the FortiPortal System Log.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46777?
CVE-2025-46777 is classified as a medium severity vulnerability due to potential exposure of sensitive information.
How do I fix CVE-2025-46777?
To mitigate CVE-2025-46777, upgrade Fortinet FortiPortal to versions 7.4.0 or above, or ensure you are using versions 7.2.6 or 7.0.10 or later.
Who is affected by CVE-2025-46777?
CVE-2025-46777 affects users of Fortinet FortiPortal versions 7.4.0, 7.2.0 through 7.2.5, and 7.0.0 through 7.0.9.
What type of attack is possible with CVE-2025-46777?
CVE-2025-46777 may allow authenticated attackers with read-only admin permissions to access encrypted secrets via system logs.
Is there a workaround for CVE-2025-46777?
Currently, the recommended action is to upgrade to a secure version as there is no effective workaround to prevent exposure.