Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Blitter
New Contributor

Forticlient 7.4 VPN - libcrypto/libssl 3.1.5.0 Vulnerabilities

Hello All,

 

The Microsoft Defender Endpoint vulnerability scanner is detecting the following vulnerable files created as part of the Forticlient 7.4 VPN Installer, all with the version number 3.1.5.0:

c:\program files\fortinet\forticlient\libcrypto-3-x64.dll
c:\program files\fortinet\forticlient\libssl-3-x64.dll
c:\program files\fortinet\forticlient\x86\libcrypto-3.dll
c:\program files\fortinet\forticlient\x86\libssl-3.dll

The listed CVE's against these files from MDE Show as:
CVE-2024-2511
CVE-2024-4603
CVE-2024-4741
CVE-2024-5535
CVE-2024-6119

Is the Forticlient 7.4 VPN software vulnerable to these CVE's because of the libcrypto/libssl dlls present in it's install directorys?

1 Solution
spoojary
Staff
Staff

The FortiClient 7.4 VPN software is not vulnerable to the CVEs mentioned due to the libcrypto/libssl DLLs present in its installation directories. FortiClient EMS 7.4.0 is no longer vulnerable to specific CVE references, as mentioned in the release notes. For further information on vulnerabilities and patches, you can visit the FortiGuard Center at https://fortiguard.com/psirt.

Siddhanth Poojary

View solution in original post

1 REPLY 1
spoojary
Staff
Staff

The FortiClient 7.4 VPN software is not vulnerable to the CVEs mentioned due to the libcrypto/libssl DLLs present in its installation directories. FortiClient EMS 7.4.0 is no longer vulnerable to specific CVE references, as mentioned in the release notes. For further information on vulnerabilities and patches, you can visit the FortiGuard Center at https://fortiguard.com/psirt.

Siddhanth Poojary
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors