Fortinet Forticlient vulnerabilities

83 known vulnerabilities affecting fortinet/forticlient.

Total CVEs
83
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH54MEDIUM24LOW4

Vulnerabilities

Page 2 of 5
CVE-2024-36507HIGHCVSS 7.8≥ 7.0.0, < 7.0.13≥ 7.2.0, < 7.2.5+1 more2024-11-12
CVE-2024-36507 [HIGH] CWE-426 CVE-2024-36507: A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering.
nvd
CVE-2024-36513HIGHCVSS 8.8≥ 6.4.0, ≤ 6.4.10≥ 7.0.0, < 7.0.13+1 more2024-11-12
CVE-2024-36513 [HIGH] CWE-270 CVE-2024-36513: A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.
nvd
CVE-2024-40592MEDIUMCVSS 6.7≥ 6.4.0, < 7.2.5v7.4.02024-11-12
CVE-2024-40592 [HIGH] CWE-347 CVE-2024-40592: An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS ver An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package via a race condition during the installation process.
nvd
CVE-2024-31489HIGHCVSS 8.1≥ 7.0.0, < 7.0.12≥ 7.2.0, < 7.2.3+2 more2024-09-10
CVE-2024-31489 [MEDIUM] CWE-295 CVE-2024-31489: AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2. AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11, FortiClientLinux 7.2.0, 7.0.0 through 7.0.11 and FortiClientMac 7.0.0 through 7.0.11, 7.2.0 through 7.2.4 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel betwe
nvd
CVE-2024-35282MEDIUMCVSS 4.6≥ 6.0.0, ≤ 7.2.52024-09-10
CVE-2024-35282 [MEDIUM] CWE-316 CVE-2024-35282: A cleartext storage of sensitive information in memory vulnerability [CWE-316] affecting FortiClient A cleartext storage of sensitive information in memory vulnerability [CWE-316] affecting FortiClient VPN iOS 7.2 all versions, 7.0 all versions, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an unauthenticated attacker that has physical access to a jailbroken device to obtain cleartext passwords via keychain dump.
nvd
CVE-2022-45856MEDIUMCVSS 5.9≥ 5.0, < 7.2.1≥ 6.4, < 7.2.5+2 more2024-09-10
CVE-2022-45856 [MEDIUM] CWE-295 CVE-2022-45856: An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7 An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4, FortiClientLinux 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4, FortiClientAndroid 6.4 all versions, 7.0 all versions, 7.2.0 and FortiClientiOS 5.6 a
nvd
CVE-2024-3661HIGHCVSS 7.6≥ 6.4.0, < 7.2.5v7.4.02024-05-06
CVE-2024-3661 [HIGH] CWE-306 CVE-2024-3661: DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-bas DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the V
nvd
CVE-2024-31492HIGHCVSS 7.8≥ 7.0.6, < 7.0.11≥ 7.2.0, < 7.2.42024-04-10
CVE-2024-31492 [HIGH] CWE-73 CVE-2024-31492: An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process.
nvd
CVE-2023-45590HIGHCVSS 8.8≥ 7.0.6, < 7.0.11v7.0.3+2 more2024-04-09
CVE-2023-45590 [CRITICAL] CWE-94 CVE-2023-45590: An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7. An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4 allows attacker to execute unauthorized code or commands via tricking a FortiClientLinux user into visiting a malicious website
nvd
CVE-2023-41840HIGHCVSS 7.8v7.0.9v7.2.0+1 more2023-11-14
CVE-2023-41840 [HIGH] CWE-426 CVE-2023-41840: A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to per A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path.
nvd
CVE-2022-40681HIGHCVSS 7.1≥ 6.0.0, ≤ 6.0.10≥ 6.2.0, ≤ 6.2.9+2 more2023-11-14
CVE-2022-40681 [HIGH] CWE-863 CVE-2022-40681: A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6. A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to cause denial of service via sending a crafted request to a specific named pipe.
nvd
CVE-2023-33304MEDIUMCVSS 5.5≥ 7.0.0, ≤ 7.0.9v7.2.0+1 more2023-11-14
CVE-2023-33304 [MEDIUM] CWE-798 CVE-2023-33304: A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2. A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system protections via the use of static credentials.
nvd
CVE-2023-37939LOWCVSS 3.3≥ 6.2.0, ≤ 6.2.9≥ 6.4.0, ≤ 6.4.9+4 more2023-10-10
CVE-2023-37939 [LOW] CWE-200 CVE-2023-37939: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions, Linux 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions and Mac 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions, 6.2 all versions, may allow a local authenticated
nvd
CVE-2022-33877MEDIUMCVSS 5.5≥ 6.4.0, ≤ 6.4.8≥ 7.0.0, ≤ 7.0.62023-06-13
CVE-2022-33877 [HIGH] CWE-276 CVE-2022-33877: An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 thro An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated attacker to tamper with files in the installation folder, if FortiClient or FortiConverter is in
nvd
CVE-2022-40682HIGHCVSS 7.8≥ 6.0.0, ≤ 6.0.10≥ 6.2.0, ≤ 6.2.9+2 more2023-04-11
CVE-2022-40682 [HIGH] CWE-863 CVE-2022-40682: A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6. A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe.
nvd
CVE-2023-22635HIGHCVSS 7.8≥ 4.0.0, ≤ 5.6.6≥ 6.0.0, ≤ 6.4.10+1 more2023-04-11
CVE-2023-22635 [HIGH] CWE-494 CVE-2023-22635: A download of code without Integrity check vulnerability [CWE-494] in FortiClientMac version 7.0.0 t A download of code without Integrity check vulnerability [CWE-494] in FortiClientMac version 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions, 5.6 all versions, 5.4 all versions, 5.2 all versions, 5.0 all versions and 4.0 all versions may allow a local attacker to escalate their privileges via modifying the installer upon upgr
nvd
CVE-2022-42470HIGHCVSS 7.8≥ 6.0.0, ≤ 6.0.10≥ 6.2.0, ≤ 6.2.9+2 more2023-04-11
CVE-2022-42470 [HIGH] CWE-23 CVE-2022-42470: A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4 A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe.
nvd
CVE-2022-43946HIGHCVSS 8.1≥ 6.0.0, < 7.0.82023-04-11
CVE-2022-43946 [HIGH] CWE-732 CVE-2022-43946: Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732 Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on the same file sharing network to execute commands via writing data into a windows pipe.
nvd
CVE-2022-33878MEDIUMCVSS 5.5≥ 7.0.0, ≤ 7.0.52022-11-02
CVE-2022-33878 [LOW] CWE-200 CVE-2022-33878: An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiClient An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiClient for Mac versions 7.0.0 through 7.0.5 may allow a local authenticated attacker to obtain the SSL-VPN password in cleartext via running a logstream for the FortiTray process in the terminal.
nvd
CVE-2022-26113HIGHCVSS 7.1≥ 6.0.0, ≤ 6.0.10≥ 6.2.0, ≤ 6.2.9+2 more2022-07-19
CVE-2022-26113 [HIGH] CWE-269 CVE-2022-26113: An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.10 may allow a local attacker to perform an arbitrary file write on the system.
nvd