PT-2024-34335 · Fortinet · Forticlientwindows

Published

2024-11-15

·

Updated

2025-06-11

·

CVE-2024-50564

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Fortinet FortiClientWindows versions 6.4.x through 7.4.0
Description: A use of a hard-coded cryptographic key in Fortinet FortiClientWindows may allow a low-privileged user to decrypt interprocess communication via a monitoring named pipe.
Recommendations: For versions 6.4.x, consider disabling the use of hard-coded cryptographic keys until a patch is available. For versions 7.0.x, restrict access to the monitoring named pipe to minimize the risk of exploitation. For versions 7.2.x, avoid using the hard-coded cryptographic key in interprocess communication until the issue is resolved. For version 7.4.0, update to a version that does not use a hard-coded cryptographic key to resolve the issue.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2025-09556
CVE-2024-50564

Affected Products

Forticlientwindows