CVE-2024-40593
published 2025-12-11CVE-2024-40593: A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions…
PriorityP421medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.10%
1.0th percentile
A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions, FortiOS 7.6.0, FortiOS 7.4.4, FortiOS 7.2.7, FortiOS 7.0.14, FortiPortal 6.0 all versions may allow an authenticated admin to retrieve a certificate's private key via the device's admin shell.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | >= 6.4.0 < 7.2.6 | 7.2.6 |
| fortinet | fortianalyzer | 6.4.0 – 6.4.15 | — |
| fortinet | fortianalyzer | 7.0.0 – 7.0.15 | — |
| fortinet | fortianalyzer | 7.2.0 – 7.2.5 | — |
| fortinet | fortianalyzer | >= 7.4.0 < 7.4.3 | 7.4.3 |
| fortinet | fortianalyzer | 7.4.0 – 7.4.2 | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 6.4.0 < 7.2.6 | 7.2.6 |
| fortinet | fortimanager | 6.4.0 – 6.4.15 | — |
| fortinet | fortimanager | 7.0.0 – 7.0.15 | — |
| fortinet | fortimanager | 7.2.0 – 7.2.5 | — |
| fortinet | fortimanager | >= 7.4.0 < 7.4.3 | 7.4.3 |
| fortinet | fortimanager | 7.4.0 – 7.4.2 | — |
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortiportal | — | — |
| fortinet | fortiportal | 6.0.0 – 6.0.15 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Private key readable by admin
vendor_fortinet·2025-12-11·CVSS 6.0
CVE-2024-40593 [MEDIUM] CWE-320 Private key readable by admin
FG-IR-24-133: Private key readable by admin
A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions, FortiOS 7.6.0, FortiOS 7.4.4, FortiOS 7.2.7, FortiOS 7.0.14, FortiPortal 6.0 all versions may allow an authenticated admin to retrieve a certificate's private key via the device's admin shell.
CVEs: CVE-2024-40593
CWEs: CWE-320
CVSS: 6.0 (medium)
Affected products: FortiAnalyzer, FortiManager, FortiOS, FortiPortal, Fortinet
GHSA
GHSA-6vww-5qwh-3c68: A key management errors vulnerability in Fortinet FortiAnalyzer 7
ghsa_unreviewed·2025-12-11
CVE-2024-40593 [MEDIUM] GHSA-6vww-5qwh-3c68: A key management errors vulnerability in Fortinet FortiAnalyzer 7
A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions, FortiOS 7.6.0, FortiOS 7.4.4, FortiOS 7.2.7, FortiOS 7.0.14, FortiPortal 6.0 all versions may allow an authenticated admin to retrieve a certificate's private key via the device's admin shell.
No detection rules found.
No public exploits indexed.
2025-12-11
Published