Home

Description

A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13 and FortiClientLinux 7.4.0 through 7.4.2, 7.2.0 through 7.2.7, 7.0.0 through 7.0.13 may permit a local authenticated user to retrieve VPN password via memory dump, due to JavaScript's garbage collector

PUBLISHED Reserved 2024-10-24 | Published 2024-12-18 | Updated 2025-08-27 | Assigner fortinet




MEDIUM: 4.9CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N/E:F/RL:X/RC:X

Problem types

Information disclosure

Product status

Default status
unaffected

7.4.0 (semver)
affected

7.2.0 (semver)
affected

7.0.0 (semver)
affected

Default status
unaffected

7.4.0 (semver)
affected

7.2.0 (semver)
affected

7.0.0 (semver)
affected

Default status
unaffected

7.4.0
affected

7.2.0 (semver)
affected

7.0.0 (semver)
affected

References

fortiguard.fortinet.com/psirt/FG-IR-23-278

cve.org (CVE-2024-50570)

nvd.nist.gov (CVE-2024-50570)

Download JSON