Hardcoded Encryption Key Used for Named Pipe Communication
Summary
A use of hard-coded cryptographic key (CWE-321) vulnerability in FortiClient Windows may allow a low-privileged user to decrypt interprocess communication via monitoring named pipe.
| Version | Affected | Solution |
|---|---|---|
| FortiClientWindows 7.4 | 7.4.0 | Upgrade to 7.4.1 or above |
| FortiClientWindows 7.2 | 7.2.0 through 7.2.8 | Upgrade to 7.2.9 or above |
| FortiClientWindows 7.0 | 7.0 all versions | Migrate to a fixed release |
| FortiClientWindows 6.4 | 6.4 all versions | Migrate to a fixed release |
Acknowledgement
Fortinet is pleased to thank Nir Chako from Pentera for reporting this vulnerability under responsible disclosureTimeline
2025-01-14: Initial publication2025-04-16: adding 7.2.9 to fixed versions