PT-2024-34337 · Fortinet · Forticlientwindows+1

Published

2024-12-18

·

Updated

2024-12-19

·

CVE-2024-50570

CVSS v3.1

5.0

Medium

VectorAV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: FortiClientWindows versions 7.0.0 through 7.0.13 FortiClientWindows versions 7.2.0 through 7.2.6 FortiClientWindows versions 7.4.0 through 7.4.1 FortiClientLinux versions 7.0.0 through 7.0.13 FortiClientLinux versions 7.2.0 through 7.2.7 FortiClientLinux versions 7.4.0 through 7.4.2
Description: A Cleartext Storage of Sensitive Information issue may permit a local authenticated user to retrieve VPN password via memory dump, due to JavaScript's garbage collector. This could allow unauthorized access to sensitive information.
Recommendations: For FortiClientWindows versions 7.0.0 through 7.0.13, update to a version that fixes the Cleartext Storage of Sensitive Information issue. For FortiClientWindows versions 7.2.0 through 7.2.6, update to a version that fixes the Cleartext Storage of Sensitive Information issue. For FortiClientWindows versions 7.4.0 through 7.4.1, update to a version that fixes the Cleartext Storage of Sensitive Information issue. For FortiClientLinux versions 7.0.0 through 7.0.13, update to a version that fixes the Cleartext Storage of Sensitive Information issue. For FortiClientLinux versions 7.2.0 through 7.2.7, update to a version that fixes the Cleartext Storage of Sensitive Information issue. For FortiClientLinux versions 7.4.0 through 7.4.2, update to a version that fixes the Cleartext Storage of Sensitive Information issue. As a temporary workaround, consider disabling JavaScript or restricting access to sensitive information until a patch is available.

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03721
CVE-2024-50570

Affected Products

Forticlientlinux
Forticlientwindows