Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-24473


A exposure of sensitive system information to an unauthorized control sphere in Fortinet FortiClientWindows versions 7.2.0 through 7.2.1 may allow an unauthorized remote attacker to view application information via navigation to a hosted webpage, if Windows is configured to accept incoming connections to port 8053 (non-default setup)


Published

2025-05-28T08:15:21.230

Last Modified

2025-06-04T15:38:01.880

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 3.7 (LOW)

Weaknesses
  • Type: Primary
    CWE-497
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet forticlient < 7.2.2 Yes

References