Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-17543


Users' VPN authentication credentials are unsafely encrypted in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2335 and below versions, due to the use of a static encryption key and weak encryption algorithms.


Published

2018-04-26T20:29:00.243

Last Modified

2024-11-21T03:18:08.213

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-326

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet forticlient ≤ 5.6.0 Yes
Application fortinet forticlient ≤ 5.6.0 Yes
Application fortinet forticlient_sslvpn_client ≤ 4.4.2335 Yes

References