cbcvebase.

Fortinet Forticlient vulnerabilities

85 known vulnerabilities affecting fortinet/forticlient.

Total CVEs
85
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH55MEDIUM25LOW4

Vulnerabilities

Page 5 of 5
CVE-2015-1569P4MEDIUMCVSS 4.3v5.2.0282015-02-10
CVE-2015-1569 [MEDIUM] CWE-310 CVE-2015-1569: Fortinet FortiClient 5.2.028 for iOS does not validate certificates, which makes it easier for man-i Fortinet FortiClient 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof SSL VPN servers via a crafted certificate.
nvd
CVE-2025-24473P4LOWCVSS 3.7≥ 7.2.0, < 7.2.22025-05-28
CVE-2025-24473 [LOW] CWE-497 CVE-2025-24473: A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortin A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an unauthorized remote attacker to view application information via navigation to a hosted webpage, if Windows is configured to accept incoming connections to p
nvd
CVE-2021-43204P4MEDIUMCVSS 4.4≥ 5.0.0, ≤ 5.0.11≥ 5.4.0, ≤ 5.4.5+34 more2021-12-09
CVE-2021-43204 [MEDIUM] CVE-2021-43204: A improper control of a resource through its lifetime in Fortinet FortiClientWindows version 6.4.1 a A improper control of a resource through its lifetime in Fortinet FortiClientWindows version 6.4.1 and 6.4.0, version 6.2.9 and below, version 6.0.10 and below allows attacker to cause a complete denial of service of its components via changes of directory access permissions.
nvd
CVE-2024-50564P4LOWCVSS 3.3≥ 6.4.0, < 7.2.9v7.4.02025-01-14
CVE-2024-50564 [LOW] CWE-321 CVE-2024-50564: A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versio A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged user to decrypt interprocess communication via monitoring named piped.
nvd
CVE-2023-37939P4LOWCVSS 3.3≥ 6.2.0, ≤ 6.2.9≥ 6.4.0, ≤ 6.4.9+4 more2023-10-10
CVE-2023-37939 [LOW] CWE-200 CVE-2023-37939: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions, Linux 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions and Mac 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions, 6.2 all versions, may allow a local authenticated
nvd
Fortinet Forticlient vulnerabilities | cvebase