CVE-2025-55717: Medium severity Fortinet FortiMail vulnerability
A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all versions, FortiRecorder 6.4 all versions, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6 may allow an authenticated malicious administrator to obtain user's secrets via CLI commands. Practical exploitability is limited by conditions out of the control of the attacker: An admin must log in to the targeted device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55717?
CVE-2025-55717 is classified as a high-severity vulnerability due to the risk of exposing sensitive information.
How do I fix CVE-2025-55717?
To fix CVE-2025-55717, upgrade Fortinet FortiMail and FortiRecorder to the latest versions where the vulnerability is patched.
What products are affected by CVE-2025-55717?
CVE-2025-55717 affects Fortinet FortiMail versions 7.0.0 through 7.6.2 and Fortinet FortiRecorder versions 6.4 and above.
What type of vulnerability is CVE-2025-55717?
CVE-2025-55717 is a cleartext storage of sensitive information vulnerability, classified under CWE-312.
Why is CVE-2025-55717 a concern for users?
CVE-2025-55717 poses a concern for users because it can lead to unauthorized access to sensitive information stored in cleartext.