VYPR

Forticlient

by Fortinet

CVEs (91)

  • CVE-2024-36507HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering.

  • CVE-2023-22635HigApr 11, 2023
    risk 0.47cvss 7.3epss 0.00

    A download of code without Integrity check vulnerability [CWE-494] in FortiClientMac version 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions, 5.6 all versions, 5.4 all versions, 5.2 all versions, 5.0 all versions and 4.0 all versions may allow a local…

  • CVE-2025-62676HigFeb 10, 2026
    risk 0.46cvss 7.1epss 0.00

    An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to…

  • CVE-2022-40681HigNov 14, 2023
    risk 0.46cvss 7.1epss 0.00

    A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to cause denial of service via sending a crafted request to a specific named pipe.

  • CVE-2022-33877HigJun 13, 2023
    risk 0.46cvss 7.0epss 0.00

    An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated attacker to tamper…

  • CVE-2021-22127HigApr 6, 2022
    risk 0.46cvss 7.1epss 0.00

    An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x before 6.2.9 may allow an unauthenticated attacker to execute arbitrary code on the host operating system as root via tricking the user into connecting to a…

  • CVE-2019-16155HigFeb 7, 2020
    risk 0.46cvss 7.1epss 0.00

    A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to overwrite system files as root with arbitrary content through system backup file via specially crafted "BackupConfig" type IPC client requests to the fctsched…

  • CVE-2025-57716MedOct 14, 2025
    risk 0.44cvss 6.7epss 0.00

    An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClient Online Installer…

  • CVE-2024-52968MedFeb 11, 2025
    risk 0.44cvss 6.7epss 0.00

    An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password.

  • CVE-2024-40586MedFeb 11, 2025
    risk 0.44cvss 6.7epss 0.00

    An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe.

  • CVE-2024-31489MedSep 10, 2024
    risk 0.44cvss 6.8epss 0.00

    AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11, FortiClientLinux 7.2.0, 7.0.0 through 7.0.11 and FortiClientMac 7.0.0 through 7.0.11, 7.2.0 through 7.2.4 may allow a remote and unauthenticated attacker…

  • CVE-2021-44167MedMay 11, 2022
    risk 0.44cvss 6.8epss 0.01

    An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6.4.7 and below, 7.0.2 and below may allow an unauthenticated attacker to access sensitive information in log files and directories…

  • CVE-2021-26089MedJul 12, 2021
    risk 0.44cvss 6.7epss 0.00

    An improper symlink following in FortiClient for Mac 6.4.3 and below may allow an non-privileged user to execute arbitrary privileged shell commands during installation phase.

  • CVE-2019-17652MedFeb 6, 2020
    risk 0.42cvss 6.5epss 0.01

    A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to cause FortiClient processes running under root priviledge crashes via sending specially crafted "StartAvCustomScan" type IPC client requests to the fctsched…

  • CVE-2019-16152MedFeb 6, 2020
    risk 0.42cvss 6.5epss 0.01

    A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to cause FortiClient processes running under root privilege crashes via sending specially crafted IPC client requests to the fctsched process due the nanomsg not…

  • CVE-2020-9291MedJun 1, 2020
    risk 0.41cvss 6.3epss 0.01

    An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain elevated privileges via exhausting the pool of temporary file names combined with a symbolic link attack.

  • CVE-2019-5585MedApr 9, 2019
    risk 0.40cvss 6.1epss 0.00

    An improper access control vulnerability in FortiClientMac before 6.0.5 may allow an attacker to affect the application's performance via modifying the contents of a file used by several FortiClientMac processes.

  • CVE-2025-31365MedOct 14, 2025
    risk 0.38cvss 5.8epss 0.00

    An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrary code on the victim's host via tricking the user into visiting a malicious…

  • CVE-2018-9195MedNov 21, 2019
    risk 0.38cvss 5.9epss 0.02

    Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify information (URL/SPAM services in FortiOS 5.6, and URL/SPAM/AV services in FortiOS 6.0.; URL rating in…

  • CVE-2025-54660MedNov 18, 2025
    risk 0.36cvss 5.5epss 0.00

    An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a local attacker to run the application step by step and retrieve the saved VPN user password