Private key readable by admin

Summary

A key management error vulnerability [CWE-320] in FortiManager, FortiAnalyzer and FortiPortal may allow an authenticated admin to retrieve a certificate's private key via the device's admin shell.

Version Affected Solution
FortiAnalyzer 7.6 Not affected Not Applicable
FortiAnalyzer 7.4 7.4.0 through 7.4.2 Upgrade to 7.4.3 or above
FortiAnalyzer 7.2 7.2.0 through 7.2.5 Upgrade to 7.2.6 or above
FortiAnalyzer 7.0 7.0 all versions Migrate to a fixed release
FortiAnalyzer 6.4 6.4 all versions Migrate to a fixed release
FortiManager 7.6 Not affected Not Applicable
FortiManager 7.4 7.4.0 through 7.4.2 Upgrade to 7.4.3 or above
FortiManager 7.2 7.2.0 through 7.2.5 Upgrade to 7.2.6 or above
FortiManager 7.0 7.0 all versions Migrate to a fixed release
FortiManager 6.4 6.4 all versions Migrate to a fixed release
FortiOS 7.6 7.6.0 Upgrade to 7.6.1 or above
FortiOS 7.4 7.4.4 Upgrade to 7.4.5 or above
FortiOS 7.2 7.2.7 Upgrade to 7.2.8 or above
FortiOS 7.0 7.0.14 Upgrade to 7.0.15 or above
FortiOS 6.4 Not affected Not Applicable
FortiPortal 7.4 Not affected Not Applicable
FortiPortal 7.2 Not affected Not Applicable
FortiPortal 7.0 Not affected Not Applicable
FortiPortal 6.0 6.0 all versions Migrate to a fixed release
Follow the recommended upgrade path using our tool at: https://docs.fortinet.com/upgrade-tool

Acknowledgement

Internally discovered and reported by Yonghui Han of Fortinet Product Security team.

Timeline

2025-12-09: Initial publication
2025-12-10: Added FAZ 7.0 and 6.4 banch as affected