Improper Cryptographic Signature Verification in FortiClient for macOS
CVE-2024-40592

6.7MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
12 November 2024

Summary

A vulnerability in FortiClient for macOS allows local authenticated attackers to exploit an improper verification of cryptographic signatures. This occurs due to a race condition during installation, which could lead to the replacement of the legitimate installer with a malicious package, potentially jeopardizing user security.

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.