ZeroHour

CVE-2024-54019

CVSS 3.1
6.5 medium
EPSS
<1%p5
Published
()
Modified
Description

A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection.

Vendors
fortinet
Products
forticlient
Weakness
CWE-297
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.