Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-42530 | A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0, and 6.4.10 through 6.4.0 allows low privilege attacker to execute arbitrary code with high privilege via spoofed named pipe messages. |
Solution
Please upgrade to FortiClientWindows version 7.4.1 or above Please upgrade to FortiClientWindows version 7.2.5 or above Please upgrade to FortiClientWindows version 7.0.13 or above
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-199 |
|
Tue, 21 Jan 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet forticlient
|
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:* cpe:2.3:a:fortinet:forticlient:7.4.0:*:*:*:*:windows:*:* |
|
| Vendors & Products |
Fortinet forticlient
|
Wed, 13 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet forticlientwindows |
|
| CPEs | cpe:2.3:a:fortinet:forticlientwindows:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet forticlientwindows |
|
| Metrics |
ssvc
|
Wed, 13 Nov 2024 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0, and 6.4.10 through 6.4.0 allows low privilege attacker to execute arbitrary code with high privilege via spoofed named pipe messages. | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-11-13T14:43:08.240Z
Reserved: 2024-09-27T16:19:24.136Z
Link: CVE-2024-47574
Updated: 2024-11-13T14:42:53.753Z
Status : Analyzed
Published: 2024-11-13T12:15:16.313
Modified: 2025-01-21T22:21:03.137
Link: CVE-2024-47574
No data.
OpenCVE Enrichment
No data.
EUVD