- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiClient VPN v7.4.2.1737 Using EOL Version of OpenSSL Library v3.1.7
Hello Fortinet Community,
I recently updated to the latest version of FortiClient VPN v7.4.2.1737 software and noticed that it is using an End-of-Life (EOL) version of the OpenSSL library, specifically v3.1.7. Given the importance of maintaining up-to-date security protocols, I am concerned about the potential vulnerabilities associated with using an outdated library.
Could anyone provide information on whether Fortinet has plans to address this issue in upcoming updates? Is there a timeline for when a fix might be implemented?
The affected paths are:
c:\program files\fortinet\forticlient\libcrypto-3-x64.dll
c:\program files\fortinet\forticlient\libssl-3-x64.dll
c:\program files\fortinet\forticlient\x86\libcrypto-3.dll
c:\program files\fortinet\forticlient\x86\libssl-3.dll
- Labels:
-
FortiClient
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiClient 7.4.2 was released before EOL date of OpenSSL 3.1 (2025-03-14)
https://openssl-library.org/policies/releasestrat/
Newer versions will use updated library files if required.
