FG-IR-23-278: Credentials can be dumped from memory
A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClient Windows and FortiClient Linux may permit a local authenticated user to retrieve VPN password via memory dump, due to JavaScript's garbage collector
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-23-278?
The severity of FG-IR-23-278 is classified as medium due to the potential exposure of sensitive information.
How do I fix FG-IR-23-278?
To fix FG-IR-23-278, upgrade FortiClient Windows to version 7.4.2 or later, or FortiClient Linux to version 7.4.3 or later.
Who is affected by FG-IR-23-278?
FG-IR-23-278 affects users of FortiClient Windows and FortiClient Linux versions prior to the specified fixed versions.
What information is at risk in FG-IR-23-278?
FG-IR-23-278 risks exposing VPN passwords stored in cleartext, which could be accessed by local authenticated users.
Is there a workaround for FG-IR-23-278?
Currently, there are no official workarounds for FG-IR-23-278, and users are advised to upgrade to safe versions.