QID 379145

Date Published: 2024-01-18

QID 379145: FortiClient Hard-Coded Credentials Vulnerability (FG-IR-23-108)

A use of hard-coded credentials vulnerability [CWE-798] in FortiClient for Windows may allow an attacker to bypass system protections via the use of static credentials.
Affected Versions:
FortiClientWindows version 7.2.0 through 7.2.1 FortiClientWindows version 7.0.0 through 7.0.9

QID Detection Logic (Authenticated) :
These checks for vulnerable version of FortiClient.

Successful exploitation of this vulnerability may allow an attacker to bypass system protections via the use of static credentials.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 4.9 severity.
  • Solution
    Users are advised to upgrade to the latest version FortiClient. Please refer FG-IR-23-108 for further information.
    Vendor References

    CVEs related to QID 379145

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-23-108 URL Logo www.fortiguard.com/psirt/FG-IR-23-108