CVE-2025-31514

Severity
4.3MEDIUM
EPSS
0.0%
top 87.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14

Description

An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an attacker with at least read-only privileges to retrieve sensitive 2FA-related information via observing logs or via diagnose command.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:NExploitability: 1.2 | Impact: 1.4

Affected Packages4 packages

NVDfortinet/fortios6.4.07.6.4
CVEListV5fortinet/fortios7.6.07.6.2+4
NVDfortinet/fortiproxy7.0.07.6.4
CVEListV5fortinet/fortiproxy7.6.07.6.3+3

🔴Vulnerability Details

2
CVEList
CVE-2025-31514: An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS 72025-10-14
GHSA
GHSA-54gp-3xh8-g5mg: An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS 72025-10-14

📋Vendor Advisories

1
Fortinet
Insertion of Sensitive 2FA Information in logs and debug command2025-10-14
CVE-2025-31514 (MEDIUM CVSS 4.3) | An Insertion of Sensitive Informati | cvebase.io