CVE-2025-24473

A exposure of sensitive system information to an unauthorized control sphere in Fortinet FortiClientWindows versions 7.2.0 through 7.2.1 may allow an unauthorized remote attacker to view application information via navigation to a hosted webpage, if Windows is configured to accept incoming connections to port 8053 (non-default setup)
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*

History

04 Jun 2025, 15:38

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://fortiguard.fortinet.com/psirt/FG-IR-24-548 - () https://fortiguard.fortinet.com/psirt/FG-IR-24-548 - Vendor Advisory
CPE cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*
First Time Fortinet forticlient
Fortinet

28 May 2025, 15:01

Type Values Removed Values Added
Summary
  • (es) Una exposición de información confidencial del sistema a una esfera de control no autorizada en Fortinet FortiClientWindows versiones 7.2.0 a 7.2.1 puede permitir que un atacante remoto no autorizado vea información de la aplicación a través de la navegación a una página web alojada, si Windows está configurado para aceptar conexiones entrantes al puerto 8053 (configuración no predeterminada)

28 May 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-28 08:15

Updated : 2025-06-04 15:38


NVD link : CVE-2025-24473

Mitre link : CVE-2025-24473

CVE.ORG link : CVE-2025-24473


JSON object : View

Products Affected

fortinet

  • forticlient
CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

NVD-CWE-noinfo