Home
MEDIUM: 4.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N/E:F/RL:X/RC:XDefault status
unaffected
7.4.0 (semver)
affected
7.2.0 (semver)
affected
7.0.0 (semver)
affected
Default status
unaffected
7.4.0 (semver)
affected
7.2.0 (semver)
affected
7.0.0 (semver)
affected
Default status
unaffected
7.4.0
affected
7.2.0 (semver)
affected
7.0.0 (semver)
affected
Description
A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13 and FortiClientLinux 7.4.0 through 7.4.2, 7.2.0 through 7.2.7, 7.0.0 through 7.0.13 may permit a local authenticated user to retrieve VPN password via memory dump, due to JavaScript's garbage collector
Problem types
Product status
7.4.0 (semver)
7.2.0 (semver)
7.0.0 (semver)
7.4.0 (semver)
7.2.0 (semver)
7.0.0 (semver)
7.4.0
7.2.0 (semver)
7.0.0 (semver)
References
fortiguard.fortinet.com/psirt/FG-IR-23-278