cbcvebase.

Fortinet Forticlient vulnerabilities

84 known vulnerabilities affecting fortinet/forticlient.

Total CVEs
84
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH54MEDIUM25LOW4

Vulnerabilities

Page 1 of 5
CVE-2024-50570P2MEDIUMCVSS 5.0Exploited≥ 7.0.0, < 7.0.14≥ 7.0.0, < 7.2.8+3 more2024-12-18
CVE-2024-50570 [MEDIUM] CWE-312 CVE-2024-50570: A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 thr A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13 and FortiClientLinux 7.4.0 through 7.4.2, 7.2.0 through 7.2.7, 7.0.0 through 7.0.13 may permit a local authenticated user to retrieve VPN password via memory dump, due to JavaScript's garbage colle
nvd
CVE-2015-5736P3HIGHCVSS 7.2PoC≤ 5.2.32015-09-03
CVE-2015-5736 [HIGH] CWE-264 CVE-2015-5736: The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitr The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel privileges by setting the callback function in a (1) 0x220024 or (2) 0x220028 ioctl call.
nvd
CVE-2019-17658P3CRITICALCVSS 9.8≥ 6.0.0, ≤ 6.0.9≥ 6.2.0, ≤ 6.2.22020-03-12
CVE-2019-17658 [CRITICAL] CWE-428 CVE-2019-17658: An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path.
nvd
CVE-2023-45590P3HIGHCVSS 8.8≥ 7.0.6, < 7.0.11v7.0.3+2 more2024-04-09
CVE-2023-45590 [HIGH] CWE-94 CVE-2023-45590: An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7. An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4 allows attacker to execute unauthorized code or commands via tricking a FortiClientLinux user into visiting a malicious website
nvd
CVE-2024-3661P3HIGHCVSS 7.6≥ 6.4.0, < 7.2.5v7.4.02024-05-06
CVE-2024-3661 [HIGH] CWE-306 CVE-2024-3661: DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-bas DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the V
nvd
CVE-2017-14184P3HIGHCVSS 8.8fixed in 5.6.02017-12-15
CVE-2017-14184 [HIGH] CWE-200 CVE-2017-14184: An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions allows regular users to see each other's VPN authentication credentials due to improperly secured storage locations.
nvd
CVE-2024-31489P3HIGHCVSS 8.1≥ 7.0.0, < 7.0.12≥ 7.2.0, < 7.2.3+2 more2024-09-10
CVE-2024-31489 [HIGH] CWE-295 CVE-2024-31489: AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2. AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11, FortiClientLinux 7.2.0, 7.0.0 through 7.0.11 and FortiClientMac 7.0.0 through 7.0.11, 7.2.0 through 7.2.4 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between
nvd
CVE-2024-47574P3HIGHCVSS 7.8≥ 6.4.0, < 7.0.13≥ 7.2.0, < 7.2.5+1 more2024-11-13
CVE-2024-47574 [HIGH] CWE-288 CVE-2024-47574: A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7. A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0, and 6.4.10 through 6.4.0 allows low privilege attacker to execute arbitrary code with high privilege via spoofed named pipe messages.
nvd
CVE-2016-8493P3HIGHCVSS 8.8v5.4.1v5.4.22017-06-26
CVE-2016-8493 [HIGH] CWE-264 CVE-2016-8493: In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability.
nvd
CVE-2024-52968P3HIGHCVSS 8.4≥ 7.0.11, < 7.0.13≥ 7.2.3, < 7.2.5+1 more2025-02-11
CVE-2024-52968 [HIGH] CWE-287 CVE-2024-52968: An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain i An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password.
nvd
CVE-2022-43946P3HIGHCVSS 8.1≥ 6.0.0, < 7.0.82023-04-11
CVE-2022-43946 [HIGH] CWE-732 CVE-2022-43946: Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732 Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on the same file sharing network to execute commands via writing data into a windows pipe.
nvd
CVE-2021-44169P3HIGHCVSS 8.8≥ 6.0.0, ≤ 6.0.10≥ 6.2.0, ≤ 6.2.9+2 more2022-04-06
CVE-2021-44169 [HIGH] CWE-665 CVE-2021-44169: A improper initialization in Fortinet FortiClient (Windows) version 6.0.10 and below, version 6.2.9 A improper initialization in Fortinet FortiClient (Windows) version 6.0.10 and below, version 6.2.9 and below, version 6.4.7 and below, version 7.0.3 and below allows attacker to gain administrative privileges via placing a malicious executable inside the FortiClient installer's directory.
nvd
CVE-2024-36513P3HIGHCVSS 8.8≥ 6.4.0, ≤ 6.4.10≥ 7.0.0, < 7.0.13+1 more2024-11-12
CVE-2024-36513 [HIGH] CWE-270 CVE-2024-36513: A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.
nvd
CVE-2021-22127P3HIGHCVSS 8.0fixed in 6.2.9≥ 6.4.0, < 6.4.32022-04-06
CVE-2021-22127 [HIGH] CWE-78 CVE-2021-22127: An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x before 6.2.9 may allow an unauthenticated attacker to execute arbitrary code on the host operating system as root via tricking the user into connecting to a network with a malicious name.
nvd
CVE-2025-57741P3HIGHCVSS 7.8≥ 7.0.0, < 7.2.12≥ 7.4.0, < 7.4.42025-10-14
CVE-2025-57741 [HIGH] CWE-732 CVE-2025-57741: An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7 An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local attacker to run arbitrary code or commands via LaunchDaemon hijacking.
nvd
CVE-2026-24018P3HIGHCVSS 7.8≥ 7.2.2, < 7.2.13≥ 7.4.0, < 7.4.52026-03-10
CVE-2026-24018 [HIGH] CWE-61 CVE-2026-24018: A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7. A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.
nvd
CVE-2025-46373P3HIGHCVSS 7.8≥ 7.2.0, < 7.2.9≥ 7.4.0, < 7.4.42025-11-18
CVE-2025-46373 [HIGH] CWE-122 CVE-2025-46373: A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7. A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.8 may allow an authenticated local IPSec user to execute arbitrary code or commands via "fortips_74.sys". The attacker would need to bypass the Windows heap integrity protections
nvd
CVE-2017-7344P3HIGHCVSS 8.1≤ 5.4.3v5.6.02017-12-14
CVE-2017-7344 [HIGH] CVE-2017-7344: A privilege escalation in Fortinet FortiClient Windows 5.4.3 and earlier as well as 5.6.0 allows att A privilege escalation in Fortinet FortiClient Windows 5.4.3 and earlier as well as 5.6.0 allows attacker to gain privilege via exploiting the Windows "security alert" dialog thereby popping up when the "VPN before logon" feature is enabled and an untrusted certificate chain.
nvd
CVE-2025-47761P3HIGHCVSS 7.8≥ 7.2.0, < 7.2.10≥ 7.4.0, < 7.4.42025-11-18
CVE-2025-47761 [HIGH] CWE-782 CVE-2025-47761: An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.9 may allow an authenticated local user to execute unauthorized code via fortips driver. Success of the attack would require bypassing the Windows memory protections such as Hea
nvd
CVE-2021-44167P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.0.8≥ 6.2.0, ≤ 6.2.9+2 more2022-05-11
CVE-2021-44167 [HIGH] CWE-732 CVE-2021-44167: An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6.4.7 and below, 7.0.2 and below may allow an unauthenticated attacker to access sensitive information in log files and directories via symbolic links.
nvd