CVE-2025-55717
published 2026-03-10CVE-2025-55717: A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4…
PriorityP416medium4CVSS 3.1
AVLACHPRHUIRSUCHINAN
EPSS
0.08%
0.3th percentile
A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all versions, FortiRecorder 6.4 all versions, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6 may allow an authenticated malicious administrator to obtain user's secrets via CLI commands. Practical exploitability is limited by conditions out of the control of the attacker: An admin must log in to the targeted device.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortimail | — | — |
| fortinet | fortimail | >= 7.0.0 < 7.0.9 | 7.0.9 |
| fortinet | fortimail | 7.0.0 – 7.0.8 | — |
| fortinet | fortimail | >= 7.2.0 < 7.2.8 | 7.2.8 |
| fortinet | fortimail | 7.2.0 – 7.2.7 | — |
| fortinet | fortimail | >= 7.4.0 < 7.4.5 | 7.4.5 |
| fortinet | fortimail | 7.4.0 – 7.4.4 | — |
| fortinet | fortimail | >= 7.6.0 < 7.6.3 | 7.6.3 |
| fortinet | fortimail | 7.6.0 – 7.6.2 | — |
| fortinet | fortinet | — | — |
| fortinet | fortirecorder | — | — |
| fortinet | fortirecorder | >= 6.4.0 < 7.2.4 | 7.2.4 |
| fortinet | fortirecorder | 6.4.0 – 6.4.6 | — |
| fortinet | fortirecorder | 7.0.0 – 7.0.6 | — |
| fortinet | fortirecorder | 7.2.0 – 7.2.3 | — |
| fortinet | fortivoice | — | — |
| fortinet | fortivoice | — | — |
| fortinet | fortivoice | >= 7.0.0 < 7.0.7 | 7.0.7 |
| fortinet | fortivoice | 7.0.0 – 7.0.6 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2h2g-hg5x-83g2: A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7
ghsa_unreviewed·2026-03-10
CVE-2025-55717 [MEDIUM] CWE-312 GHSA-2h2g-hg5x-83g2: A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7
A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all versions, FortiRecorder 6.4 all versions, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6 may allow an authenticated malicious administrator to obtain user's secrets via CLI commands. Practical exploitability is limited by conditions out of the control of the attacker: An admin must log in to the targeted device.
Fortinet
Insecure Exposure of Plaintext Passwords in Debug Logs
vendor_fortinet·2026-03-10·CVSS 4.0
CVE-2025-55717 [MEDIUM] CWE-312 Insecure Exposure of Plaintext Passwords in Debug Logs
FG-IR-26-080: Insecure Exposure of Plaintext Passwords in Debug Logs
A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all versions, FortiRecorder 6.4 all versions, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6 may allow an authenticated malicious administrator to obtain user's secrets via CLI commands. Practical exploitability is limited by conditions out of the control of the attacker: An admin must log in to the targeted device.
CVEs: CVE-2025-55717
CWEs: CWE-312
CVSS: 4.0 (medium)
Affected products: FortiMail, FortiRecorder, FortiVoice, Fortinet
No detection rules found.
No public exploits indexed.
2026-03-10
Published