Cleartext Storage Vulnerability in FortiClient Products by Fortinet
CVE-2024-50570

4.9MEDIUM

What is CVE-2024-50570?

A vulnerability exists in FortiClient software that allows local authenticated users to access sensitive information, specifically VPN passwords, through JavaScript's garbage collector. This flaw occurs due to the cleartext storage of sensitive data in memory. Attackers with local access can exploit this weakness by performing a memory dump, compromising the confidentiality of user credentials. It is essential for organizations using these versions of FortiClient to assess their systems and consider remediation strategies.

Affected Version(s)

FortiClientLinux 7.4.0 <= 7.4.2

FortiClientLinux 7.2.0 <= 7.2.7

FortiClientLinux 7.0.0 <= 7.0.13

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.