CVE-2024-31489: High severity fortinet forticlient vulnerability
AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11, FortiClientLinux 7.2.0, 7.0.0 through 7.0.11 and FortiClientMac 7.0.0 through 7.0.11, 7.2.0 through 7.2.4 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiGate and the FortiClient during the ZTNA tunnel creation
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31489?
CVE-2024-31489 has a severity rating that varies based on the specific configuration and potential impact on the system.
How do I fix CVE-2024-31489?
To fix CVE-2024-31489, users should upgrade to FortiClient versions 7.2.5 or later for Linux, Windows, and macOS.
What types of attacks can exploit CVE-2024-31489?
CVE-2024-31489 can be exploited by remote and unauthenticated attackers to perform Man-in-the-Middle attacks.
Which versions of FortiClient are affected by CVE-2024-31489?
FortiClient versions 7.0.0 through 7.0.11 and 7.2.0 through 7.2.4 are affected by CVE-2024-31489.
Is CVE-2024-31489 specific to a particular operating system?
CVE-2024-31489 affects FortiClient on Windows, Linux, and macOS.