CVE-2025-55717

Published Mar 10, 2026

Last updated 4 days ago

Overview

Description
A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all versions, FortiRecorder 6.4 all versions, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6 may allow an authenticated malicious administrator to obtain user's secrets via CLI commands. Practical exploitability is limited by conditions out of the control of the attacker: An admin must log in to the targeted device.
Source
psirt@fortinet.com
NVD status
Analyzed
Products
fortivoice, fortirecorder, fortimail

Risk scores

CVSS 3.1

Type
Primary
Base score
4
Impact score
3.6
Exploitability score
0.3
Vector string
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

psirt@fortinet.com
CWE-312

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.