Low SEVERITY — Vulnerability

Hardcoded Encryption Key Used for VPN Saved Passwords

CVSSv3 Score: 2.1 A Missing Authorization [CWE-862] in FortiClient Windows may allow an authenticated local attacker to decrypt a currently logged in users VPN password via use of an unprotected DLL function. Revised on 2026-05-12 00:00:00

Platform
FortiGate / FortiOS
CVSS Score
2.1/10
Advisory
FG-IR-26-129
Published
12 May 2026
Views
5
Primary source: Review the official advisory at fortiguard.fortinet.com Kaynağa Git

Özet

CVSSv3 Score: 2.1 A Missing Authorization [CWE-862] in FortiClient Windows may allow an authenticated local attacker to decrypt a currently logged in users VPN password via use of an unprotected DLL function. Revised on 2026-05-12 00:00:00

Kaynak

Bu kayıt otomatik olarak içeri alınmıştır; yayına almadan önce içeriği doğrulayın.

FortiGate / FortiOS — Related Advisories

VIEW ALL →