CVE-2025-46752

A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the enrollment code.

Severity
Medium 4.2
CVSS 3.1
Adjacent, local or physical access what this means
Exploited
Not listed
EPSS
0.002
4.4th percentile
Discovered by
Vendor
Vendor advisory field
Published
Oct 16, 2025
Assigned by fortinet

Description

A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the enrollment code.

Weakness: CWE-532

Affected products

Vendor Product Category Matched by
Fortinet FortiDLP Endpoint / EDR cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiDLP

Credit

Internally discovered and reported by Leslie Zhou of Fortinet Product Security team.

Vendor remediation

Upgrade to FortiDLP version 12.1.0 or above

Something wrong here?