CVE Vulnerabilities

CVE-2024-47574

Authentication Bypass Using an Alternate Path or Channel

Published: Nov 13, 2024 | Modified: Jan 21, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0, and 6.4.10 through 6.4.0 allows low privilege attacker to execute arbitrary code with high privilege via spoofed named pipe messages.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
ForticlientFortinet6.4.0 (including)7.0.13 (excluding)
ForticlientFortinet7.2.0 (including)7.2.5 (excluding)
ForticlientFortinet7.4.0 (including)7.4.0 (including)

Potential Mitigations

References