Fortinet Forticlient vulnerabilities

83 known vulnerabilities affecting fortinet/forticlient.

Total CVEs
83
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH54MEDIUM24LOW4

Vulnerabilities

Page 4 of 5
CVE-2019-17652MEDIUMCVSS 6.5≤ 6.2.12020-02-06
CVE-2019-17652 [MEDIUM] CWE-787 CVE-2019-17652: A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to cause FortiClient processes running under root priviledge crashes via sending specially crafted "StartAvCustomScan" type IPC client requests to the fctsched process due the argv data not been well sanitized.
nvd
CVE-2019-17650HIGHCVSS 7.8≤ 6.2.12019-11-21
CVE-2019-17650 [HIGH] CWE-78 CVE-2019-17650: An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root processes, may allow a local user of the system on which FortiClient is running to execute unauthorized code as root by bypassing a security check.
nvd
CVE-2018-9195MEDIUMCVSS 5.9≤ 6.0.6≤ 6.2.12019-11-21
CVE-2018-9195 [MEDIUM] CWE-798 CVE-2018-9195: Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a M Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify information (URL/SPAM services in FortiOS 5.6, and URL/SPAM/AV services in FortiOS 6.0.; URL rating in FortiClient) sent and received from Fortiguard severs by decrypting these messag
nvd
CVE-2019-15704MEDIUMCVSS 5.5≥ 6.0.0, ≤ 6.0.7v6.2.02019-11-21
CVE-2019-15704 [MEDIUM] CWE-311 CVE-2019-15704: A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read sensitive information logged in the console window when the user connects to an SSL VPN Gateway.
nvd
CVE-2019-6692HIGHCVSS 7.8≤ 6.2.02019-10-24
CVE-2019-6692 [HIGH] CWE-427 CVE-2019-6692: A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a p A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker to perform arbitrary code execution via forging that DLL.
nvd
CVE-2018-9193HIGHCVSS 7.8≤ 6.0.42019-05-30
CVE-2018-9193 [HIGH] CVE-2018-9193: A researcher has disclosed several vulnerabilities against FortiClient for Windows version 6.0.5 and A researcher has disclosed several vulnerabilities against FortiClient for Windows version 6.0.5 and below, version 5.6.6, the combination of these vulnerabilities can turn into an exploit chain, which allows a user to gain system privileges on Microsoft Windows.
nvd
CVE-2018-13368HIGHCVSS 7.8≤ 6.0.42019-05-30
CVE-2018-13368 [HIGH] CVE-2018-13368: A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attacker t A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attacker to execute unauthorized code or commands via the command injection.
nvd
CVE-2018-9191HIGHCVSS 7.8≤ 6.0.42019-05-30
CVE-2018-9191 [HIGH] CVE-2018-9191: A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attackers A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attackers to execute unauthorized code or commands via the named pipe responsible for Forticlient updates.
nvd
CVE-2019-5589HIGHCVSS 7.8fixed in 6.0.62019-05-28
CVE-2019-5589 [HIGH] CWE-426 CVE-2019-5589: An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) m An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthenticated, remote attacker with control over the directory in which FortiClientOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious .dll files in that directory.
nvd
CVE-2018-9190MEDIUMCVSS 5.5≤ 6.0.22019-02-08
CVE-2018-9190 [MEDIUM] CWE-476 CVE-2018-9190: A null pointer dereference vulnerability in Fortinet FortiClientWindows 6.0.2 and earlier allows att A null pointer dereference vulnerability in Fortinet FortiClientWindows 6.0.2 and earlier allows attacker to cause a denial of service via the NDIS miniport driver.
nvd
CVE-2017-17543HIGHCVSS 7.5≤ 5.6.02018-04-26
CVE-2017-17543 [HIGH] CWE-326 CVE-2017-17543: Users' VPN authentication credentials are unsafely encrypted in Fortinet FortiClient for Windows 5.6 Users' VPN authentication credentials are unsafely encrypted in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2335 and below versions, due to the use of a static encryption key and weak encryption algorithms.
nvd
CVE-2017-14184HIGHCVSS 8.8fixed in 5.6.02017-12-15
CVE-2017-14184 [HIGH] CWE-200 CVE-2017-14184: An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions allows regular users to see each other's VPN authentication credentials due to improperly secured storage locations.
nvd
CVE-2017-7344HIGHCVSS 8.1≤ 5.4.3v5.6.02017-12-14
CVE-2017-7344 [HIGH] CVE-2017-7344: A privilege escalation in Fortinet FortiClient Windows 5.4.3 and earlier as well as 5.6.0 allows att A privilege escalation in Fortinet FortiClient Windows 5.4.3 and earlier as well as 5.6.0 allows attacker to gain privilege via exploiting the Windows "security alert" dialog thereby popping up when the "VPN before logon" feature is enabled and an untrusted certificate chain.
nvd
CVE-2016-8493HIGHCVSS 8.8v5.4.1v5.4.22017-06-26
CVE-2016-8493 [HIGH] CWE-264 CVE-2016-8493: In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability.
nvd
CVE-2015-5735HIGHCVSS 7.2≤ 5.2.32015-09-03
CVE-2015-5735 [HIGH] CWE-264 CVE-2015-5735: The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fo The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to write to arbitrary memory locations via a 0x226108 ioctl call.
nvd
CVE-2015-5736HIGHCVSS 7.2PoC≤ 5.2.32015-09-03
CVE-2015-5736 [HIGH] CWE-264 CVE-2015-5736: The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitr The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel privileges by setting the callback function in a (1) 0x220024 or (2) 0x220028 ioctl call.
nvd
CVE-2015-5737HIGHCVSS 7.2≤ 5.2.32015-09-03
CVE-2015-5737 [HIGH] CWE-264 CVE-2015-5737: The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, (4) mdare64_52.sys, and (5) Fortishi The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, (4) mdare64_52.sys, and (5) Fortishield.sys drivers in Fortinet FortiClient before 5.2.4 do not properly restrict access to the API for management of processes and the Windows registry, which allows local users to obtain a privileged handle to a PID and possibly have unspecified other impac
nvd
CVE-2015-4077LOWCVSS 2.1PoC≤ 5.2.32015-09-03
CVE-2015-4077 [LOW] CWE-200 CVE-2015-4077: The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fo The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to read arbitrary kernel memory via a 0x22608C ioctl call.
nvd
CVE-2015-1570MEDIUMCVSS 4.3v5.2.3.091v5.2.0282015-02-10
CVE-2015-1570 [MEDIUM] CWE-310 CVE-2015-1570: The Endpoint Control protocol implementation in Fortinet FortiClient 5.2.3.091 for Android and 5.2.0 The Endpoint Control protocol implementation in Fortinet FortiClient 5.2.3.091 for Android and 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof servers via a crafted certificate.
nvd
CVE-2015-1569MEDIUMCVSS 4.3v5.2.0282015-02-10
CVE-2015-1569 [MEDIUM] CWE-310 CVE-2015-1569: Fortinet FortiClient 5.2.028 for iOS does not validate certificates, which makes it easier for man-i Fortinet FortiClient 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof SSL VPN servers via a crafted certificate.
nvd