CVE-2024-52968

An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password.

Severity
Medium 5.8
CVSS 3.1
Exploited
Not listed
EPSS
0.002
14.9th percentile
Discovered by
Vendor
Vendor advisory field
Published
Feb 11, 2025
Assigned by fortinet

Description

An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password.

Weakness: CWE-287

Affected products

Vendor Product Category Matched by
Fortinet FortiClient Endpoint / EDR cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiClientMac

Credit

Internally discovered and reported by Abdul Majid Mohammed of Fortinet QA team.

Vendor remediation

Please upgrade to FortiClientMac version 7.4.1 or above Please upgrade to FortiClientMac version 7.2.5 or above Please upgrade to FortiClientMac version 7.0.13 or above

Something wrong here?