#VU119482 Inclusion of Sensitive Information in Log Files in Fortinet, Inc products - CVE-2024-47570
Published: December 9, 2025
FortiOS
FortiPAM
FortiProxy
FortiSRA
Fortinet, Inc
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into log files. A remote read-only administrator can retrieve API tokens of other administrators via observing REST API logs, if REST API logging is enabled (non-default configuration).