CVE-2024-40592

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Nov 12, 2024
Updated: Nov 14, 2024
CWE ID 347

Summary

CVE-2024-40592 is a vulnerability affecting FortiClient for MacOS. Versions 7.4.0, 7.2.4 and below, 7.0.10 and below, and 6.4.10 and below are impacted. This issue involves an improper verification of cryptographic signatures (CWE-347). An attacker who is already authenticated on the system can exploit this flaw during the installation process, potentially swapping the installer with a malicious package due to a race condition. This could result in the installation of unintended software, posing a security risk to the affected system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Fortinet FortiClient

Affected Vendors

  • Fortinet