CVE-2024-35281Improper Isolation or Compartmentalization in Fortinet Forticlientmac

Severity
7.8HIGHNVD
CNA2.5
EPSS
0.1%
top 82.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13

Description

An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5fortinet/fortivoiceucdesktop3.0.03.0.16
CVEListV5fortinet/forticlientmac7.4.07.4.2+2
NVDfortinet/forticlient7.0.07.2.9+1
NVDfortinet/fortifone_softclient3.0.03.0.16

🔴Vulnerability Details

2
GHSA
GHSA-9qx4-7755-7gxr: An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 72025-05-13
CVEList
CVE-2024-35281: An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 72025-05-13

📋Vendor Advisories

1
Fortinet
An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version...2025-05-13
CVE-2024-35281 — Fortinet Forticlientmac vulnerability | cvebase