Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FlorentG
New Contributor

FortiClient 7.4.3.1790 – OpenSSL 3.1.7 DLLs flagged by Defender (CVE‑2024‑13176)

Hello,

We noticed that FortiClient 7.4.3.1790 loads the following OpenSSL‑related DLLs:

  • libcrypto-3-x64.dll
  • libssl-3-x64.dll
  • libcrypto-3.dll
  • libssl-3.dll

These files appear to be based on OpenSSL 3.1.7, and Microsoft Defender for Endpoint is associating them with:

  • CVE‑2024‑13176
  • plus one additional vulnerability affecting OpenSSL 3.1.x

Could you please clarify the following?

  1. For the OpenSSL 3.1.7 components bundled with FortiClient 7.4.3.1790:

    • Are these builds affected by the vulnerabilities?
    • Or are they patched/customized by Fortinet, even though this is not mentioned in the release notes?
  2. Is there an existing or upcoming FortiClient build that includes a more recent OpenSSL version (e.g. 3.1.8 or 3.1.9)?

  3. Is there a Fortinet security advisory confirming whether FortiClient is impacted (or not) by CVE‑2024‑13176?

We are trying to determine whether this should trigger remediation or if it is likely a false positive from Microsoft Defender.

Thank you.

1 REPLY 1
mpapisetty
Staff
Staff

Hi @FlorentG ,

As a part of security best practice, Fortinet upgrades 3rd party components from time to time. The OpenSSL version can be confirmed by checking the file under "... Fortinet\FortiClient\x86\libcrypto-3.dll". The properties of the file would show you the version of OpenSSL. 

Version 7.4.4 should have OpenSSL 3.4.1 and 7.4.5 comes with 3.5.4. You can upgrade to these versions and get the latest OpenSSL DLLs. 

HTH
Manoj Papisetty
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors