CVE-2025-24473

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/05/2025
Last modified:
04/06/2025

Description

A exposure of sensitive system information to an unauthorized control sphere in Fortinet FortiClientWindows versions 7.2.0 through 7.2.1 may allow an unauthorized remote attacker to view application information via navigation to a hosted webpage, if Windows is configured to accept incoming connections to port 8053 (non-default setup)

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:* 7.2.0 (including) 7.2.2 (excluding)


References to Advisories, Solutions, and Tools