Cleartext Storage Vulnerability in FortiClient Products by Fortinet
CVE-2024-50570
4.9MEDIUM
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 18 December 2024
What is CVE-2024-50570?
A vulnerability exists in FortiClient software that allows local authenticated users to access sensitive information, specifically VPN passwords, through JavaScript's garbage collector. This flaw occurs due to the cleartext storage of sensitive data in memory. Attackers with local access can exploit this weakness by performing a memory dump, compromising the confidentiality of user credentials. It is essential for organizations using these versions of FortiClient to assess their systems and consider remediation strategies.
Affected Version(s)
FortiClientLinux 7.4.0 <= 7.4.2
FortiClientLinux 7.2.0 <= 7.2.7
FortiClientLinux 7.0.0 <= 7.0.13