SB20240910156 - Information disclosure in FortiClient for iOS
Published: September 10, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Cleartext storage of sensitive information (CVE-ID: CVE-2024-35282)
CWE-ID: CWE-312 - Cleartext Storage of Sensitive Information
CVSSv4: CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows an attacker to gain access to sensitive information.
The vulnerability exists due to cleartext storage of sensitive information in memory vulnerability. An attacker with physical access to a jailbroken device to obtain cleartext passwords via keychain dump.
Remediation
Install update from vendor's website.