Cleartext Storage Vulnerability in FortiClient Products by Fortinet
CVE-2024-50570
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 18 December 2024
What is CVE-2024-50570?
A vulnerability exists in FortiClient software that allows local authenticated users to access sensitive information, specifically VPN passwords, through JavaScript's garbage collector. This flaw occurs due to the cleartext storage of sensitive data in memory. Attackers with local access can exploit this weakness by performing a memory dump, compromising the confidentiality of user credentials. It is essential for organizations using these versions of FortiClient to assess their systems and consider remediation strategies.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FortiClientLinux 7.4.0 <= 7.4.2
FortiClientLinux 7.2.0 <= 7.2.7
FortiClientLinux 7.0.0 <= 7.0.13
References
CVSS V3.1
Timeline
Vulnerability published