Hardcoded Encryption Key Used for Named Pipe Communication

Summary

A use of hard-coded cryptographic key (CWE-321) vulnerability in FortiClient Windows may allow a low-privileged user to decrypt interprocess communication via monitoring named pipe.

Version Affected Solution
FortiClientWindows 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiClientWindows 7.2 7.2.0 through 7.2.8 Upgrade to 7.2.9 or above
FortiClientWindows 7.0 7.0 all versions Migrate to a fixed release
FortiClientWindows 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Nir Chako from Pentera for reporting this vulnerability under responsible disclosure

Timeline

2025-01-14: Initial publication
2025-04-16: adding 7.2.9 to fixed versions