CVE-2024-47574

A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0, and 6.4.10 through 6.4.0 allows low privilege attacker to execute arbitrary code with high privilege via spoofed named pipe messages.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
fortinetCNA
7.4 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
VendorProductVersion
fortinetforticlientwindows
7.2.4 ≤
𝑥
≤ 7.2.4
fortinetforticlientwindows
7.0.12 ≤
𝑥
≤ 7.0.12
fortinetforticlientwindows
6.4.10 ≤
𝑥
≤ 6.4.10
fortinetforticlient
6.4.0 ≤
𝑥
< 7.0.13
fortinetforticlient
7.2.0 ≤
𝑥
< 7.2.5
fortinetforticlient
7.4.0
𝑥
= Vulnerable software versions