VYPR

Forticlient

by Fortinet

CVEs (91)

  • CVE-2019-16150MedJun 4, 2020
    risk 0.36cvss 5.5epss 0.01

    Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local storage or the configuration backup file to decrypt the sensitive data via…

  • CVE-2019-15704MedNov 21, 2019
    risk 0.36cvss 5.5epss 0.00

    A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read sensitive information logged in the console window when the user connects to an SSL VPN Gateway.

  • CVE-2018-9190MedFeb 8, 2019
    risk 0.36cvss 5.5epss 0.00

    A null pointer dereference vulnerability in Fortinet FortiClientWindows 6.0.2 and earlier allows attacker to cause a denial of service via the NDIS miniport driver.

  • CVE-2021-41030MedDec 8, 2021
    risk 0.35cvss 5.4epss 0.01

    An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4 and below may allow an unauthenticated attacker to impersonate an existing user by intercepting and re-using valid SAML authentication messages.

  • CVE-2024-50570MedDec 18, 2024
    risk 0.33cvss 5.0epss 0.00

    A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13 and FortiClientLinux 7.4.0 through 7.4.2, 7.2.0 through 7.2.7, 7.0.0 through 7.0.13 may permit a local authenticated user to…

  • CVE-2024-54019MedJun 10, 2025
    risk 0.31cvss 4.8epss 0.00

    A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection.

  • CVE-2020-9295MedMar 17, 2025
    risk 0.31cvss 4.7epss 0.00

    FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version 6.00137 and below may not immediately detect certain types of malformed or non-standard RAR archives, potentially…

  • CVE-2022-45856MedSep 10, 2024
    risk 0.31cvss 4.8epss 0.00

    An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4, FortiClientLinux 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4,…

  • CVE-2023-33304MedNov 14, 2023
    risk 0.29cvss 4.4epss 0.00

    A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system protections via the use of static credentials.

  • CVE-2021-43204MedDec 9, 2021
    risk 0.29cvss 4.4epss 0.00

    A improper control of a resource through its lifetime in Fortinet FortiClientWindows version 6.4.1 and 6.4.0, version 6.2.9 and below, version 6.0.10 and below allows attacker to cause a complete denial of service of its components via changes of directory access permissions.

  • CVE-2021-43205MedApr 6, 2022
    risk 0.28cvss 4.3epss 0.01

    An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and below and 6.2.9 and below may allow an unauthenticated attacker to access the confighandler webserver via external binaries.

  • CVE-2021-36167MedDec 9, 2021
    risk 0.28cvss 4.3epss 0.01

    An improper authorization vulnerabiltiy [CWE-285] in FortiClient Windows versions 7.0.0 and 6.4.6 and below and 6.2.8 and below may allow an unauthenticated attacker to bypass the webfilter control via modifying the session-id paramater.

  • CVE-2024-35282MedSep 10, 2024
    risk 0.27cvss 4.2epss 0.00

    A cleartext storage of sensitive information in memory vulnerability [CWE-316] affecting FortiClient VPN iOS 7.2 all versions, 7.0 all versions, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an unauthenticated attacker that has physical access to a jailbroken…

  • CVE-2025-24473LowMay 28, 2025
    risk 0.24cvss 3.7epss 0.00

    A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an unauthorized remote attacker to view application information via navigation to a…

  • CVE-2024-50564LowJan 14, 2025
    risk 0.21cvss 3.3epss 0.00

    A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged user to decrypt interprocess communication via monitoring named piped.

  • CVE-2023-37939LowOct 10, 2023
    risk 0.21cvss 3.3epss 0.00

    An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions, Linux 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions and Mac 7.2.0 through 7.2.1, 7.0 all…

  • CVE-2021-42754LowNov 2, 2021
    risk 0.21cvss 3.2epss 0.00

    An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authenticated attacker to hijack the MacOS camera without the user permission via the malicious dylib file.

  • CVE-2025-22855LowApr 8, 2025
    risk 0.18cvss 2.7epss 0.00

    An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages containing javascript code.

  • CVE-2024-35281LowMay 13, 2025
    risk 0.16cvss 2.5epss 0.00

    An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron…

  • CVE-2026-44278LowMay 12, 2026
    risk 0.15cvss 2.3epss 0.00

    A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via

Page 4 of 5