Hello Fortinet Community,
I recently updated to the latest version of FortiClient VPN v7.4.2.1737 software and noticed that it is using an End-of-Life (EOL) version of the OpenSSL library, specifically v3.1.7. Given the importance of maintaining up-to-date security protocols, I am concerned about the potential vulnerabilities associated with using an outdated library.
Could anyone provide information on whether Fortinet has plans to address this issue in upcoming updates? Is there a timeline for when a fix might be implemented?
The affected paths are:
c:\program files\fortinet\forticlient\libcrypto-3-x64.dll
c:\program files\fortinet\forticlient\libssl-3-x64.dll
c:\program files\fortinet\forticlient\x86\libcrypto-3.dll
c:\program files\fortinet\forticlient\x86\libssl-3.dll
FortiClient 7.4.2 was released before EOL date of OpenSSL 3.1 (2025-03-14)
https://openssl-library.org/policies/releasestrat/
Newer versions will use updated library files if required.
OpenSSL libraries will be updated in the next release of FortiClient.
Thank you for reporting this.
The problem persists even though updates of forticlient VPN have been released in the meantime. When can we expect a fix?
We are using FortiClient VPN: 7.4.3.1790
kr
Daniel
User | Count |
---|---|
2534 | |
1351 | |
795 | |
641 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.