QID 379143

Date Published: 2024-02-26

QID 379143: Fortinet FortiClient Unauthorized Actor Vulnerability (FG-IR-22-246)

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Mac may allow a local authenticated attacker to obtain the SSL-VPN password in cleartext via running a logstream for the FortiTray process in the terminal.
Affected Versions:
FortiClientMac version 7.0.0 through 7.0.5

QID Detection Logic (Authenticated) :
These checks for vulnerable version of FortiClient.

Successful exploitation of the vulnerability may allow a local authenticated attacker to obtain the SSL-VPN password in cleartext via running a logstream for the FortiTray process in the terminal.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Vendor has released fix to address these vulnerabilities. Refer to FG-IR-22-246
    Vendor References

    CVEs related to QID 379143

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-22-246 URL Logo www.fortiguard.com/psirt/FG-IR-22-246