CVE-2025-61713
A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2
Severity
Low 3.8
CVSS 3.1
Exploited
Not listed
EPSS
0.001
1.5th percentile
Discovered by
Not disclosed
Published
Nov 18, 2025
Assigned by fortinet
Description
A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions may allow an authenticated attacker with read-write admin privileges to the CLI to obtain other administrators' credentials via diagnose commands.
Weakness: CWE-316
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiPAM | Identity / IAM / MFA | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiPAM
Vendor remediation
Upgrade to FortiPAM version 1.7.0 or above Upgrade to FortiPAM version 1.6.1 or above