Skip to main content
ced_rtsystem
New Member
May 29, 2025
Solved

Question about FortiClient VPN SSL and CVE-2025-0167

  • May 29, 2025
  • 2 replies
  • 2406 views

Hello,

  our "Vulnerability Scanner" detected that libcurl.dll as vulnerable to CVE-2025-0167

Vulnerable files are:

  • C:\Program Files\Fortinet\FortiClient\libcurl.dll
  • C:\Program Files\Fortinet\FortiClient\x86\libcurl.dll

We use free FortiClient VPN SSL, so we can't confirm if full paid version is vulnerable too.

We've upgraded to FortiClient VPN SSL 7.4.3, but libcurl.dll version is still vulnerable

 

Best answer by xshkurti

After going through the PSIRT website, there are no CVEs reported for this issue.

PSIRT Advisories | FortiGuard Labs

 

You can raise a request to Technical Support so we can track the issue with our FortiGuard Labs.

You can also check for libcurl.dll library to upgrade it separately:

Addressing CVE-2025-0167 vulnerability - How to upgrade curl and libcurl 8.12.0 - Microsoft Q&A

2 replies

xshkurti
Staff
xshkurtiAnswer
Staff
May 30, 2025

After going through the PSIRT website, there are no CVEs reported for this issue.

PSIRT Advisories | FortiGuard Labs

 

You can raise a request to Technical Support so we can track the issue with our FortiGuard Labs.

You can also check for libcurl.dll library to upgrade it separately:

Addressing CVE-2025-0167 vulnerability - How to upgrade curl and libcurl 8.12.0 - Microsoft Q&A

ced_rtsystem
New Member
June 3, 2025

OK, Thanks!

 

We've sent a request to Fortinet PSIRT.

 

Manually changing libcurl.dll inside C:\Program Files\Fortinet, would require us to do it again the next time we update FortiClient.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.