---
id: CVE-2024-40593
title: >-
  A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through
  7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions,
  FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager
  7.2.0 …
summary: >-
  A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through
  7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions,
  FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager
  7.2.0 …
severity: medium
cvss: 6
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-320
vendor: fortinet
product: fortianalyzer
affected:
  - 'fortianalyzer >= 6.4.0, < 7.2.6'
  - 'fortianalyzer >= 7.4.0, < 7.4.3'
  - 'fortimanager >= 6.4.0, < 7.2.6'
  - 'fortimanager >= 7.4.0, < 7.4.3'
  - fortios = 7.0.14
  - fortios = 7.2.7
  - fortios = 7.4.4
  - fortios = 7.6.0
  - 'fortiportal >= 6.0.0, <= 6.0.15'
patched:
  - fortianalyzer 7.4.3
  - fortimanager 7.4.3
published: '2025-12-11'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T00:10:00.180'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-40593'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-24-133'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.00109
epssPercentile: 0.01128
ingestedAt: '2026-10-02T01:05:54.714Z'
---

## Overview

A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions, FortiOS 7.6.0, FortiOS 7.4.4, FortiOS 7.2.7, FortiOS 7.0.14, FortiPortal 6.0 all versions may allow an authenticated admin to retrieve a certificate's private key via the device's admin shell.

## Affected

- `fortianalyzer >= 6.4.0, < 7.2.6`
- `fortianalyzer >= 7.4.0, < 7.4.3`
- `fortimanager >= 6.4.0, < 7.2.6`
- `fortimanager >= 7.4.0, < 7.4.3`
- `fortios = 7.0.14`
- `fortios = 7.2.7`
- `fortios = 7.4.4`
- `fortios = 7.6.0`
- `fortiportal >= 6.0.0, <= 6.0.15`

## Remediation

Upgrade past the affected range:

- `fortianalyzer 7.4.3`
- `fortimanager 7.4.3`
