CVE-2024-50564: Hardcoded Encryption Key Used for Named Pipe Communication
A use of hard-coded cryptographic key (CWE-321) vulnerability in FortiClient Windows may allow a low-privileged user to decrypt interprocess communication via monitoring named pipe.
Other sources
A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged user to decrypt interprocess communication via monitoring named piped.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50564?
CVE-2024-50564 has a low severity rating, indicating a lower risk to affected systems.
How do I fix CVE-2024-50564?
To remediate CVE-2024-50564, update Fortinet FortiClient to the latest version that addresses the hard-coded cryptographic key issue.
Which versions of Fortinet FortiClient are affected by CVE-2024-50564?
CVE-2024-50564 affects Fortinet FortiClient versions 7.4.0, 7.2.x, 7.0.x, and 6.4.x.
What is the impact of CVE-2024-50564?
The impact of CVE-2024-50564 allows low-privileged users to potentially decrypt interprocess communication through named pipes.
Who is the vendor for CVE-2024-50564?
The vendor for CVE-2024-50564 is Fortinet, which develops the FortiClient software.