Improper Authentication in FortiMonitor Agent
Summary
An Improper Authentication vulnerability [CWE-287] for FortiClientMac may allow an unauthenticated attacker with local access to the MacOS device to login without a password as a standard user.
| Version | Affected | Solution |
|---|---|---|
| FortiClientMac 7.4 | 7.4.0 | Upgrade to 7.4.1 or above |
| FortiClientMac 7.2 | 7.2.3 through 7.2.4 | Upgrade to 7.2.5 or above |
| FortiClientMac 7.0 | 7.0.11 through 7.0.12 | Upgrade to 7.0.13 or above |
After logging into the system, the attacker is considered a standard MacOS user with rights defined as per the vendor's specifications.