Skip to main content
cmartinson
New Member
October 4, 2017
Question

FortiClient 5.6.0.1075 Vulnerability Scan detects issues in Chrome I cannot fix

  • October 4, 2017
  • 1 reply
  • 9425 views

I recently installed FortiClient 5.6.0.1075 and ran the Vulnerability Scan. It detected 162 vulnerabilities, all having to do with Google Chrome 49.0.2618.8 and suggests that I patch the software manually since it cannot be auto-patched.

 

Two problems: One is that I only have Chrome version 61.0.3163.100 installed (as far as I know), and the other is that re-installs of Chrome and re-scans by the FortiClient Vulnerability Scan return the same results.

 

Has anyone run into this? Is it possible I'm running into conflicts with other antivirus/antimalware software I have running?

1 reply

timmertc
New Member
August 2, 2018

I have the same problem, but with Client 6.0.0 & 6.0.1

I had both Chrome and Vivaldi installed (Vivaldi uses Chromium backend). I uninstalled Chrome, scanned, still had the vulnerabilities. Uninstalled Vivaldi, scanned, still had the vulnerabilities.

I then deleted the Chrome installation folder, found the Google folder in the hidden AppData folder, deleted it, then reran the scan. Result: Still have Chrome vulnerabilities. I tried to find the same folders for Vivaldi, but it appears to clean up after itself much better than Chrome.

 

So I have 61 Critical, 316 High, 412 Medium, and 5 Low vulnerabilities, all Chrome vulnerabilities, that I can't patch  or get rid of.

 

pavol_jaco
New Member
October 23, 2018

I have the same problem, all PC are becoming not compliant and therefore are blocked. That is huge problem in production environment. Looks like I cannot rely on forticlient vulnerability modul. Also there is no notification in windows environment about vulnerabilities found. Even I have set 15 days grace period for patching vulnerabilities, nobody noticed that. Any idea how to fix this?

tanr
New Member
October 23, 2018

I would open a support ticket with TAC for this.

 

If updating Chrome on the systems doesn't fix the report it may be that you have some third party software installed that is using an outdated version of Chrome/Chromium as a backend.