← back
CVE-2024-33504

CVE-2024-33504

CVSS 3.9 LOWEPSS 0.3%CWE-321
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.9EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
11 Feb 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9, 7.0 all versions, 6.4 all versions may allow an attacker with JSON API access permissions to decrypt some secrets even if the 'private-data-encryption' setting is enabled.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N/E:P/RL:X/RC:C
Affected products
Fortinet · FortiManager

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →