CVE-2025-24473: Medium severity Fortinet FortiClient vulnerability
A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an unauthorized remote attacker to view application information via navigation to a hosted webpage, if Windows is configured to accept incoming connections to port 8053 (non-default setup)
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24473?
CVE-2025-24473 has a medium severity level due to the potential exposure of sensitive information.
How do I fix CVE-2025-24473?
To address CVE-2025-24473, update Fortinet FortiClient to version 7.2.2 or later.
What systems are affected by CVE-2025-24473?
CVE-2025-24473 affects Fortinet FortiClient versions 7.2.0 through 7.2.1 on Windows.
What kind of information can be exposed in CVE-2025-24473?
CVE-2025-24473 may allow unauthorized remote attackers to view application information.
Can I mitigate CVE-2025-24473 without updating?
Mitigation options are limited, but ensuring stricter firewall rules may help reduce exposure while waiting to update.