FG-IR-24-133: Private key readable by admin
A key management error vulnerability [CWE-320] in FortiManager, FortiAnalyzer and FortiPortal may allow an authenticated admin to retrieve a certificate's private key via the device's admin shell.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-133?
The FG-IR-24-133 vulnerability is considered critical as it allows an authenticated admin to retrieve a certificate's private key.
How do I fix FG-IR-24-133?
To fix FG-IR-24-133, update FortiManager and FortiAnalyzer to version 7.4.3 or later, or version 7.2.6 or later as applicable.
Which Fortinet products are impacted by FG-IR-24-133?
The Fortinet products affected by FG-IR-24-133 include FortiManager, FortiAnalyzer, and FortiPortal.
Is a patch available for FG-IR-24-133?
Yes, patches are available for various versions of FortiManager, FortiAnalyzer, and FortiOS to address FG-IR-24-133.
What actions should be taken if I am using a vulnerable version related to FG-IR-24-133?
If using a vulnerable version related to FG-IR-24-133, immediately upgrade to the recommended fixed versions to ensure security.