QID 376241
Date Published: 2022-01-20
QID 376241: Forticlient Telemetry protocol Vulnerability (FG-IR-21-075)
FortiClient is a comprehensive endpoint security solution.
Use of a hard-coded cryptographic key to encrypt security sensitive data in configuration in FortiClient for Windows may allow an attacker with access to the configuration or the backup file to decrypt the sensitive data via knowledge of the hard-coded key.
Affected Versions:
FortiClientWindows version 7.0.1 and below.
FortiClientWindows version 6.4.6 and below.
FortiClientLinux version 7.0.1 and below.
FortiClientLinux version 6.4.6 and below.
FortiClientMac version 7.0.1 and below.
FortiClientMac version 6.4.6 and below.
QID Detection Logic (Authenticated) :
This checks for vulnerable version of FortiClient.exe.
The vulnerability may allow an unauthenticated and network adjacent attacker to perform a man-in-the-middle attack between the EMS and the FCT via the telemetry protocol.
- FG-IR-21-075 -
www.fortiguard.com/psirt/FG-IR-21-075
CVEs related to QID 376241
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-075 |
|