CVE Vulnerabilities

CVE-2024-40592

Improper Verification of Cryptographic Signature

Published: Nov 12, 2024 | Modified: Nov 14, 2024
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package via a race condition during the installation process.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Forticlient Fortinet 6.4.0 (including) 7.2.5 (excluding)
Forticlient Fortinet 7.4.0 (including) 7.4.0 (including)

References