Use of Hard-coded Cryptographic Key in Fortinet FortiClient for Windows - #VU28499

 

Use of Hard-coded Cryptographic Key in Fortinet FortiClient for Windows - #VU28499

Published: June 2, 2020


Vulnerability identifier: #VU28499
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-321
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information on the target system.

The vulnerability exists due to presence of a hard-coded cryptographic key in the default configuration file. A remote authenticated attacker with access to the configuration or the backup file can decrypt the sensitive data on the target system. 


Affected software

Fortinet FortiClient for Windows

Remediation

Install updates from vendor's website.

Fortinet FortiClient for Windows - update to 6.4.0

External References

Related Security Bulletins