Use of Hard-coded Cryptographic Key to encrypt sensitive data

Summary

A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager may allow an attacker with JSON API access permissions to decrypt some secrets even if the 'private-data-encryption' setting is enabled.

Version Affected Solution
FortiManager 7.6 7.6.0 through 7.6.1 Upgrade to 7.6.2 or above
FortiManager 7.4 7.4.0 through 7.4.5 Upgrade to 7.4.6 or above
FortiManager 7.2 7.2.0 through 7.2.9 Upgrade to 7.2.10 or above
FortiManager 7.0 7.0 all versions Migrate to a fixed release
FortiManager 6.4 6.4 all versions Migrate to a fixed release
FortiManager Cloud 7.6 Not affected Not Applicable
FortiManager Cloud 7.4 7.4.1 through 7.4.5 Upgrade to 7.4.6 or above
FortiManager Cloud 7.2 7.2.1 through 7.2.8 Upgrade to 7.2.9 or above
FortiManager Cloud 7.0 7.0.1 through 7.0.13 Migrate to a fixed release
FortiManager Cloud 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Loic RESTOUX and Orange CERT-CC from Orange for reporting this vulnerability under responsible disclosure.

Timeline

2025-02-11: Initial publication