PT-2025-24711 · Fortinet · Forticlient

Published

2025-06-10

·

Updated

2025-06-10

·

CVE-2024-54019

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiClientWindows versions 7.0 through 7.2.6 Fortinet FortiClientWindows version 7.4.0
Description The issue is related to an improper validation of certificates with host mismatch, allowing an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection.
Recommendations For Fortinet FortiClientWindows versions 7.0 through 7.2.6, update to a version that properly validates certificates to prevent host mismatch. For Fortinet FortiClientWindows version 7.4.0, update to a version that properly validates certificates to prevent host mismatch. As a temporary workaround, consider restricting VPN connections to trusted networks and verifying the identity of VPN servers to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-09931
CVE-2024-54019

Affected Products

Forticlient