CVE-2023-33304: Medium severity fortinet forticlient ssl vpn vulnerability
Published Nov 14, 2023
·Updated
A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system protections via the use of static credentials.
Affected Software
3 affected components
Fortinet FortiClient Windows>=7.0.0<=7.0.9
Fortinet FortiClient Windows=7.2.0
Fortinet FortiClient Windows=7.2.1
Remediation
Information
Please upgrade to FortiClientWindows version 7.2.2 or above
Please upgrade to FortiClientWindows version 7.0.10 or above
Event History
Nov 14, 2023
CVE Published
06:07 PM
Data Sourced
06:07 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-33304.
2
What is the severity of CVE-2023-33304?
The severity of CVE-2023-33304 is medium.
3
How does CVE-2023-33304 affect Fortinet FortiClient?
CVE-2023-33304 affects Fortinet FortiClient versions 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 on Windows.
4
How can an attacker exploit CVE-2023-33304?
An attacker can exploit CVE-2023-33304 by bypassing system protections using hard-coded credentials.
5
Is there a fix available for CVE-2023-33304?
Yes, Fortinet has released a fix for CVE-2023-33304. It is recommended to update to the latest version of Fortinet FortiClient.