Junglewise Threat Intelligence

CVE-2025-31514: Fortinet FortiOS sensitive information disclosure in logs

CVE-2025-31514 · Severity: low · CVSS 2.7 · Published 2025-10-14

Technologies: Siemens Ruggedcom Ape1808, Fortinet FortiOS, Fortinet FortiProxy. Vendors: Siemens, Fortinet.

Executive brief

FortiOS and FortiProxy are operating systems used in Fortinet firewalls and web proxies to secure corporate networks. A vulnerability in these systems could allow an administrator with limited access to view sensitive two-factor authentication (2FA) information. While this does not allow direct outside access, it could be used by a malicious insider to compromise additional security layers.

Technical details

An Insertion of Sensitive Information into Log File vulnerability (CWE-532) exists in the GUI component of FortiOS and FortiProxy. The vulnerability allows an authenticated attacker with at least read-only privileges to retrieve sensitive 2FA-related information by observing system logs or executing specific 'diagnose' commands. The attack vector is network-based, but requires high privileges (PR:H) according to the vendor's CVSS assessment. This could lead to the disclosure of secrets used for multi-factor authentication. Users are advised to upgrade to FortiOS/FortiProxy version 7.6.4 or higher, or migrate to a fixed release for older branches.

Affected products

  • Fortinet FortiOS 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions
  • Fortinet FortiProxy 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0 all versions
  • Siemens RUGGEDCOM APE1808 All versions with Fortinet NGFW < V7.6.6

Timeline

  • 2025-10-14: advisory: Initial publication by Fortinet
  • 2025-10-14: disclosed
  • 2025-05-13: other: Siemens advisory publication (pre-dates specific CVE disclosure)

References

Related threats