Executive brief
FortiOS and FortiProxy are operating systems used in Fortinet firewalls and web proxies to secure corporate networks. A vulnerability in these systems could allow an administrator with limited access to view sensitive two-factor authentication (2FA) information. While this does not allow direct outside access, it could be used by a malicious insider to compromise additional security layers.
Technical details
An Insertion of Sensitive Information into Log File vulnerability (CWE-532) exists in the GUI component of FortiOS and FortiProxy. The vulnerability allows an authenticated attacker with at least read-only privileges to retrieve sensitive 2FA-related information by observing system logs or executing specific 'diagnose' commands. The attack vector is network-based, but requires high privileges (PR:H) according to the vendor's CVSS assessment. This could lead to the disclosure of secrets used for multi-factor authentication. Users are advised to upgrade to FortiOS/FortiProxy version 7.6.4 or higher, or migrate to a fixed release for older branches.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions
- Fortinet FortiProxy 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0 all versions
- Siemens RUGGEDCOM APE1808 All versions with Fortinet NGFW < V7.6.6
Timeline
- 2025-10-14: advisory: Initial publication by Fortinet
- 2025-10-14: disclosed
- 2025-05-13: other: Siemens advisory publication (pre-dates specific CVE disclosure)