First published: Fri Dec 15 2017(Updated: )
An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions allows regular users to see each other's VPN authentication credentials due to improperly secured storage locations.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiClient Windows | <5.6.0 | |
Fortinet Forticlient | <5.6.0 | |
Fortinet Forticlient Sslvpn Client | <4.4.2334 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14184 is an Information Disclosure vulnerability in Fortinet FortiClient for Windows, Mac OSX, and Linux.
CVE-2017-14184 has a severity score of 8.8, which is considered high.
Fortinet FortiClient for Windows versions up to 5.6.0, FortiClient for Mac OSX versions up to 5.6.0, and FortiClient SSLVPN Client for Linux versions up to 4.4.2334 are affected by CVE-2017-14184.
Regular users can see each other's VPN authentication credentials due to the vulnerability in Fortinet FortiClient.
To fix CVE-2017-14184, update Fortinet FortiClient to a version higher than 5.6.0 for Windows and Mac OSX, and higher than 4.4.2334 for Linux.