Fortinet Forticlientwindows vulnerabilities
26 known vulnerabilities affecting fortinet/forticlientwindows.
Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
HIGH15MEDIUM8LOW3
Vulnerabilities
Page 2 of 2
CVE-2026-44278P4MEDIUMCVSS 5.5≥ 7.4.0, ≤ 7.4.2≥ 7.2.0, ≤ 7.2.142026-05-12
CVE-2026-44278 [MEDIUM] CWE-321 CVE-2026-44278: A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4
A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via
nvd
CVE-2022-33877P4MEDIUMCVSS 5.5≥ 7.0.0, ≤ 7.0.6≥ 6.4.0, ≤ 6.4.82023-06-13
CVE-2022-33877 [MEDIUM] CWE-276 CVE-2022-33877: An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 thro
An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated attacker to tamper with files in the installation folder, if FortiClient or FortiConverter is
nvd
CVE-2025-54660P4MEDIUMCVSS 5.5≥ 7.4.0, ≤ 7.4.3≥ 7.2.0, ≤ 7.2.10+1 more2025-11-18
CVE-2025-54660 [MEDIUM] CWE-489 CVE-2025-54660: An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWi
An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a local attacker to run the application step by step and retrieve the saved VPN user password
nvd
CVE-2025-24473P4LOWCVSS 3.7≥ 7.2.0, ≤ 7.2.1≥ 7.0.13, ≤ 7.0.142025-05-28
CVE-2025-24473 [LOW] CWE-497 CVE-2025-24473: A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortin
A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an unauthorized remote attacker to view application information via navigation to a hosted webpage, if Windows is configured to accept incoming connections to p
nvd
CVE-2024-50564P4LOWCVSS 3.3v7.4.0≥ 7.2.0, ≤ 7.2.7+2 more2025-01-14
CVE-2024-50564 [LOW] CWE-321 CVE-2024-50564: A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versio
A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged user to decrypt interprocess communication via monitoring named piped.
nvd
CVE-2023-37939P4LOWCVSS 3.3v7.2.0≥ 7.0.0, ≤ 7.0.9+2 more2023-10-10
CVE-2023-37939 [LOW] CWE-200 CVE-2023-37939: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions, Linux 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions and Mac 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions, 6.2 all versions, may allow a local authenticated
nvd
← Previous2 / 2