cbcvebase.

Fortinet Forticlientwindows vulnerabilities

28 known vulnerabilities affecting fortinet/forticlientwindows.

Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
HIGH16MEDIUM9LOW3

Vulnerabilities

Page 2 of 2
CVE-2023-33304P4MEDIUMCVSS 5.5≥ 7.2.0, ≤ 7.2.1≥ 7.0.0, ≤ 7.0.92023-11-14
CVE-2023-33304 [MEDIUM] CWE-798 CVE-2023-33304: A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2. A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system protections via the use of static credentials.
nvd
CVE-2026-44278P4MEDIUMCVSS 5.5≥ 7.4.0, ≤ 7.4.2≥ 7.2.0, ≤ 7.2.142026-05-12
CVE-2026-44278 [MEDIUM] CWE-321 CVE-2026-44278: A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4 A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via
nvd
CVE-2022-33877P4MEDIUMCVSS 5.5≥ 7.0.0, ≤ 7.0.6≥ 6.4.0, ≤ 6.4.82023-06-13
CVE-2022-33877 [MEDIUM] CWE-276 CVE-2022-33877: An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 thro An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated attacker to tamper with files in the installation folder, if FortiClient or FortiConverter is
nvd
CVE-2025-54660P4MEDIUMCVSS 5.5≥ 7.4.0, ≤ 7.4.3≥ 7.2.0, ≤ 7.2.10+1 more2025-11-18
CVE-2025-54660 [MEDIUM] CWE-489 CVE-2025-54660: An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWi An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a local attacker to run the application step by step and retrieve the saved VPN user password
nvd
CVE-2026-84386P4MEDIUMCVSS 5.1≥ 7.4.0, ≤ 7.4.7≥ 7.2.0, ≤ 7.2.152026-09-08
CVE-2026-84386 [MEDIUM] CWE-283 CVE-2026-84386: A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClient A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via via an exposed minifilter communication port.
nvd
CVE-2025-24473P4LOWCVSS 3.7≥ 7.2.0, ≤ 7.2.1≥ 7.0.13, ≤ 7.0.142025-05-28
CVE-2025-24473 [LOW] CWE-497 CVE-2025-24473: A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortin A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an unauthorized remote attacker to view application information via navigation to a hosted webpage, if Windows is configured to accept incoming connections to p
nvd
CVE-2024-50564P4LOWCVSS 3.3v7.4.0≥ 7.2.0, ≤ 7.2.7+2 more2025-01-14
CVE-2024-50564 [LOW] CWE-321 CVE-2024-50564: A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versio A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged user to decrypt interprocess communication via monitoring named piped.
nvd
CVE-2023-37939P4LOWCVSS 3.3v7.2.0≥ 7.0.0, ≤ 7.0.9+2 more2023-10-10
CVE-2023-37939 [LOW] CWE-200 CVE-2023-37939: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions, Linux 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions and Mac 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions, 6.2 all versions, may allow a local authenticated
nvd
Fortinet Forticlientwindows vulnerabilities | cvebase