CVE-2024-52968Improper Authentication in Fortinet Forticlient

Severity
8.4HIGHNVD
CNA6.7
EPSS
0.0%
top 92.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 11

Description

An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.5 | Impact: 5.9

Affected Packages2 packages

CVEListV5fortinet/forticlientmac7.2.37.2.4+2
NVDfortinet/forticlient7.0.117.0.13+2

🔴Vulnerability Details

2
GHSA
GHSA-h55v-j7qg-4vf6: An improper authentication in Fortinet FortiClientMac 72025-02-11
CVEList
CVE-2024-52968: An improper authentication in Fortinet FortiClientMac 72025-02-11

📋Vendor Advisories

1
Fortinet
An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to Ma...2025-02-11
CVE-2024-52968 — Improper Authentication in Fortinet | cvebase