CVE-2024-40592
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a
Description
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package via a race condition during the installation process.
Weakness: CWE-347
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiClient | Endpoint / EDR | cna-assigner |
Vendor-reported products (2)
- Fortinet · FortiClientMac
- fortinet · forticlientmac
Credit
Fortinet is pleased to thank Mykola Grymalyuk from RIPEDA Consulting for reporting this vulnerability under responsible disclosure.
Vendor remediation
Please upgrade to FortiClientMac version 7.4.1 or above Please upgrade to FortiClientMac version 7.2.5 or above