CVE Vulnerabilities

CVE-2024-47574

Authentication Bypass Using an Alternate Path or Channel

Published: Nov 13, 2024 | Modified: Jan 21, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0, and 6.4.10 through 6.4.0 allows low privilege attacker to execute arbitrary code with high privilege via spoofed named pipe messages.

Weakness

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Forticlient Fortinet 6.4.0 (including) 7.0.13 (excluding)
Forticlient Fortinet 7.2.0 (including) 7.2.5 (excluding)
Forticlient Fortinet 7.4.0 (including) 7.4.0 (including)

Potential Mitigations

References