A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an unauthorized remote attacker to view application information via navigation to a hosted webpage, if Windows is configured to accept incoming connections to port 8053 (non-default setup)
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-548 | Vendor Advisory |
Configurations
History
08 Jan 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an unauthorized remote attacker to view application information via navigation to a hosted webpage, if Windows is configured to accept incoming connections to port 8053 (non-default setup) |
04 Jun 2025, 15:38
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | NVD-CWE-noinfo | |
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-24-548 - Vendor Advisory | |
| CPE | cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:* | |
| First Time |
Fortinet forticlient
Fortinet |
28 May 2025, 15:01
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
28 May 2025, 08:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-05-28 08:15
Updated : 2026-01-08 22:16
NVD link : CVE-2025-24473
Mitre link : CVE-2025-24473
CVE.ORG link : CVE-2025-24473
JSON object : View
Products Affected
fortinet
- forticlient
CWE
