CVE-2024-40592
published 2024-11-12CVE-2024-40592: An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and…
PriorityP428medium6.7CVSS 3.1
AVLACHPRLUIRSUCHIHAH
EPSS
0.13%
3.2th percentile
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package via a race condition during the installation process.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
| fortinet | forticlient | — | — |
| fortinet | forticlient | >= 6.4.0 < 7.2.5 | 7.2.5 |
| fortinet | forticlientmac | — | — |
| fortinet | forticlientmac | 6.4.0 – 6.4.10 | — |
| fortinet | forticlientmac | 7.0.0 – 7.0.10 | — |
| fortinet | forticlientmac | 7.2.0 – 7.2.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version...
vendor_fortinet·2024-11-12·CVSS 7.5
CVE-2024-40592 [HIGH] CWE-347 An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version...
FG-IR-24-022: An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version...
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package via a race condition during the installation process.
CVEs: CVE-2024-40592
CWEs: CWE-347
CVSS: 7.5 (high)
Affected products: FortiClient
GHSA
GHSA-3vq2-5g7p-fgf2: An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7
ghsa_unreviewed·2024-11-12
CVE-2024-40592 [HIGH] CWE-347 GHSA-3vq2-5g7p-fgf2: An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package via a race condition during the installation process.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-12
Published