IPsec improper validation of certificate with host mismatch

Summary

An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiClient Windows may allow an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection

Version Affected Solution
FortiClientWindows 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiClientWindows 7.2 7.2.0 through 7.2.6 Upgrade to 7.2.7 or above
FortiClientWindows 7.0 7.0 all versions Migrate to a fixed release

Timeline

2025-06-10: Initial publication