<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>FortiClient(All) - Lack of client-side certificate validation using SAML SSO</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-22-230</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2024-09-10T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2024-09-10T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2025-01-10T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            An improper certificate validation vulnerability [CWE-295] in FortiClientWindows, FortiClientMac, FortiClientLinux, FortiClientAndroid and FortiClientiOS SAML SSO feature may allow an unauthenticated attacker to man-in-the-middle the communication between the FortiClient and both the service provider and the identity provider.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Information disclosure
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Fortinet is pleased to thank Ka Lok WU, Man Hong HUE, Ngai Man POON, Sze Yiu CHAU from the department of Information Engineering, the Chinese University of Hong Kong and Christian Hilgers from indevis for reporting this vulnerability under responsible disclosure.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiClientAndroid" Type="Product Name">
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-7.2.0">FortiClientAndroid 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-7.0.7">FortiClientAndroid 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-7.0.6">FortiClientAndroid 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-7.0.3">FortiClientAndroid 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-7.0.2">FortiClientAndroid 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-7.0.0">FortiClientAndroid 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-6.4.6">FortiClientAndroid 6.4.6</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-6.4.4">FortiClientAndroid 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-6.4.1">FortiClientAndroid 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-6.0.0">FortiClientAndroid 6.0.0</FullProductName>
                </Branch>
                <Branch Name="5.6.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.6.0">FortiClientAndroid 5.6.0</FullProductName>
                </Branch>
                <Branch Name="5.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.4.2">FortiClientAndroid 5.4.2</FullProductName>
                </Branch>
                <Branch Name="5.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.4.1">FortiClientAndroid 5.4.1</FullProductName>
                </Branch>
                <Branch Name="5.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.4.0">FortiClientAndroid 5.4.0</FullProductName>
                </Branch>
                <Branch Name="5.2.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.2.8">FortiClientAndroid 5.2.8</FullProductName>
                </Branch>
                <Branch Name="5.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.2.7">FortiClientAndroid 5.2.7</FullProductName>
                </Branch>
                <Branch Name="5.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.2.6">FortiClientAndroid 5.2.6</FullProductName>
                </Branch>
                <Branch Name="5.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.2.5">FortiClientAndroid 5.2.5</FullProductName>
                </Branch>
                <Branch Name="5.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.2.4">FortiClientAndroid 5.2.4</FullProductName>
                </Branch>
                <Branch Name="5.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.2.3">FortiClientAndroid 5.2.3</FullProductName>
                </Branch>
                <Branch Name="5.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.2.2">FortiClientAndroid 5.2.2</FullProductName>
                </Branch>
                <Branch Name="5.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.2.1">FortiClientAndroid 5.2.1</FullProductName>
                </Branch>
                <Branch Name="5.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.2.0">FortiClientAndroid 5.2.0</FullProductName>
                </Branch>
                <Branch Name="5.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.0.3">FortiClientAndroid 5.0.3</FullProductName>
                </Branch>
                <Branch Name="5.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.0.2">FortiClientAndroid 5.0.2</FullProductName>
                </Branch>
                <Branch Name="5.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.0.1">FortiClientAndroid 5.0.1</FullProductName>
                </Branch>
                <Branch Name="5.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientAndroid-5.0.0">FortiClientAndroid 5.0.0</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiClientLinux" Type="Product Name">
                <Branch Name="7.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.4">FortiClientLinux 7.2.4</FullProductName>
                </Branch>
                <Branch Name="7.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.3">FortiClientLinux 7.2.3</FullProductName>
                </Branch>
                <Branch Name="7.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.2">FortiClientLinux 7.2.2</FullProductName>
                </Branch>
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.1">FortiClientLinux 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.0">FortiClientLinux 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.13" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.13">FortiClientLinux 7.0.13</FullProductName>
                </Branch>
                <Branch Name="7.0.12" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.12">FortiClientLinux 7.0.12</FullProductName>
                </Branch>
                <Branch Name="7.0.11" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.11">FortiClientLinux 7.0.11</FullProductName>
                </Branch>
                <Branch Name="7.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.10">FortiClientLinux 7.0.10</FullProductName>
                </Branch>
                <Branch Name="7.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.9">FortiClientLinux 7.0.9</FullProductName>
                </Branch>
                <Branch Name="7.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.8">FortiClientLinux 7.0.8</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.7">FortiClientLinux 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.6">FortiClientLinux 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.5">FortiClientLinux 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.4">FortiClientLinux 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.3">FortiClientLinux 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.2">FortiClientLinux 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.1">FortiClientLinux 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.0">FortiClientLinux 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-6.4.9">FortiClientLinux 6.4.9</FullProductName>
                </Branch>
                <Branch Name="6.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-6.4.8">FortiClientLinux 6.4.8</FullProductName>
                </Branch>
                <Branch Name="6.4.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-6.4.7">FortiClientLinux 6.4.7</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-6.4.4">FortiClientLinux 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-6.4.3">FortiClientLinux 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-6.4.2">FortiClientLinux 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-6.4.1">FortiClientLinux 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-6.4.0">FortiClientLinux 6.4.0</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiClientMac" Type="Product Name">
                <Branch Name="7.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.2.4">FortiClientMac 7.2.4</FullProductName>
                </Branch>
                <Branch Name="7.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.2.3">FortiClientMac 7.2.3</FullProductName>
                </Branch>
                <Branch Name="7.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.2.2">FortiClientMac 7.2.2</FullProductName>
                </Branch>
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.2.1">FortiClientMac 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.2.0">FortiClientMac 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.14" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.14">FortiClientMac 7.0.14</FullProductName>
                </Branch>
                <Branch Name="7.0.13" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.13">FortiClientMac 7.0.13</FullProductName>
                </Branch>
                <Branch Name="7.0.12" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.12">FortiClientMac 7.0.12</FullProductName>
                </Branch>
                <Branch Name="7.0.11" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.11">FortiClientMac 7.0.11</FullProductName>
                </Branch>
                <Branch Name="7.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.10">FortiClientMac 7.0.10</FullProductName>
                </Branch>
                <Branch Name="7.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.9">FortiClientMac 7.0.9</FullProductName>
                </Branch>
                <Branch Name="7.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.8">FortiClientMac 7.0.8</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.7">FortiClientMac 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.6">FortiClientMac 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.5">FortiClientMac 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.4">FortiClientMac 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.3">FortiClientMac 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.2">FortiClientMac 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.1">FortiClientMac 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-7.0.0">FortiClientMac 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.10" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.10">FortiClientMac 6.4.10</FullProductName>
                </Branch>
                <Branch Name="6.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.9">FortiClientMac 6.4.9</FullProductName>
                </Branch>
                <Branch Name="6.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.8">FortiClientMac 6.4.8</FullProductName>
                </Branch>
                <Branch Name="6.4.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.7">FortiClientMac 6.4.7</FullProductName>
                </Branch>
                <Branch Name="6.4.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.6">FortiClientMac 6.4.6</FullProductName>
                </Branch>
                <Branch Name="6.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.5">FortiClientMac 6.4.5</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.4">FortiClientMac 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.3">FortiClientMac 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.2">FortiClientMac 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.1">FortiClientMac 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientMac-6.4.0">FortiClientMac 6.4.0</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiClientWindows" Type="Product Name">
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.7">FortiClientWindows 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.6">FortiClientWindows 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.5">FortiClientWindows 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.4">FortiClientWindows 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.3">FortiClientWindows 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.2">FortiClientWindows 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.1">FortiClientWindows 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.0">FortiClientWindows 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.4.10" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.10">FortiClientWindows 6.4.10</FullProductName>
                </Branch>
                <Branch Name="6.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.9">FortiClientWindows 6.4.9</FullProductName>
                </Branch>
                <Branch Name="6.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.8">FortiClientWindows 6.4.8</FullProductName>
                </Branch>
                <Branch Name="6.4.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.7">FortiClientWindows 6.4.7</FullProductName>
                </Branch>
                <Branch Name="6.4.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.6">FortiClientWindows 6.4.6</FullProductName>
                </Branch>
                <Branch Name="6.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.5">FortiClientWindows 6.4.5</FullProductName>
                </Branch>
                <Branch Name="6.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.4">FortiClientWindows 6.4.4</FullProductName>
                </Branch>
                <Branch Name="6.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.3">FortiClientWindows 6.4.3</FullProductName>
                </Branch>
                <Branch Name="6.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.2">FortiClientWindows 6.4.2</FullProductName>
                </Branch>
                <Branch Name="6.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.1">FortiClientWindows 6.4.1</FullProductName>
                </Branch>
                <Branch Name="6.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-6.4.0">FortiClientWindows 6.4.0</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiClientiOS" Type="Product Name">
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-7.0.6">FortiClientiOS 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-7.0.5">FortiClientiOS 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-7.0.4">FortiClientiOS 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-7.0.3">FortiClientiOS 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-7.0.1">FortiClientiOS 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-7.0.0">FortiClientiOS 7.0.0</FullProductName>
                </Branch>
                <Branch Name="6.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-6.0.1">FortiClientiOS 6.0.1</FullProductName>
                </Branch>
                <Branch Name="6.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-6.0.0">FortiClientiOS 6.0.0</FullProductName>
                </Branch>
                <Branch Name="5.6.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-5.6.6">FortiClientiOS 5.6.6</FullProductName>
                </Branch>
                <Branch Name="5.6.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-5.6.5">FortiClientiOS 5.6.5</FullProductName>
                </Branch>
                <Branch Name="5.6.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-5.6.1">FortiClientiOS 5.6.1</FullProductName>
                </Branch>
                <Branch Name="5.6.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-5.6.0">FortiClientiOS 5.6.0</FullProductName>
                </Branch>
                <Branch Name="5.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-5.4.4">FortiClientiOS 5.4.4</FullProductName>
                </Branch>
                <Branch Name="5.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-5.4.3">FortiClientiOS 5.4.3</FullProductName>
                </Branch>
                <Branch Name="5.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-5.4.1">FortiClientiOS 5.4.1</FullProductName>
                </Branch>
                <Branch Name="5.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-5.4.0">FortiClientiOS 5.4.0</FullProductName>
                </Branch>
                <Branch Name="5.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-5.2.3">FortiClientiOS 5.2.3</FullProductName>
                </Branch>
                <Branch Name="5.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-5.2.2">FortiClientiOS 5.2.2</FullProductName>
                </Branch>
                <Branch Name="5.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-5.2.1">FortiClientiOS 5.2.1</FullProductName>
                </Branch>
                <Branch Name="5.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-5.2.0">FortiClientiOS 5.2.0</FullProductName>
                </Branch>
                <Branch Name="5.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-5.0.3">FortiClientiOS 5.0.3</FullProductName>
                </Branch>
                <Branch Name="5.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-5.0.2">FortiClientiOS 5.0.2</FullProductName>
                </Branch>
                <Branch Name="5.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-5.0.1">FortiClientiOS 5.0.1</FullProductName>
                </Branch>
                <Branch Name="5.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-5.0.0">FortiClientiOS 5.0.0</FullProductName>
                </Branch>
                <Branch Name="4.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-4.0.2">FortiClientiOS 4.0.2</FullProductName>
                </Branch>
                <Branch Name="4.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-4.0.1">FortiClientiOS 4.0.1</FullProductName>
                </Branch>
                <Branch Name="4.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-4.0.0">FortiClientiOS 4.0.0</FullProductName>
                </Branch>
                <Branch Name="2.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-2.0.1">FortiClientiOS 2.0.1</FullProductName>
                </Branch>
                <Branch Name="2.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientiOS-2.0.0">FortiClientiOS 2.0.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>FortiClient(All) - Lack of client-side certificate validation using SAML SSO</Title>
        <cvrf:CVE>CVE-2022-45856</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiClientAndroid-7.2.0</ProductID>
                <ProductID>FortiClientAndroid-7.0.7</ProductID>
                <ProductID>FortiClientAndroid-7.0.6</ProductID>
                <ProductID>FortiClientAndroid-7.0.3</ProductID>
                <ProductID>FortiClientAndroid-7.0.2</ProductID>
                <ProductID>FortiClientAndroid-7.0.0</ProductID>
                <ProductID>FortiClientAndroid-6.4.6</ProductID>
                <ProductID>FortiClientAndroid-6.4.4</ProductID>
                <ProductID>FortiClientAndroid-6.4.1</ProductID>
                <ProductID>FortiClientAndroid-6.0.0</ProductID>
                <ProductID>FortiClientAndroid-5.6.0</ProductID>
                <ProductID>FortiClientAndroid-5.4.2</ProductID>
                <ProductID>FortiClientAndroid-5.4.1</ProductID>
                <ProductID>FortiClientAndroid-5.4.0</ProductID>
                <ProductID>FortiClientAndroid-5.2.8</ProductID>
                <ProductID>FortiClientAndroid-5.2.7</ProductID>
                <ProductID>FortiClientAndroid-5.2.6</ProductID>
                <ProductID>FortiClientAndroid-5.2.5</ProductID>
                <ProductID>FortiClientAndroid-5.2.4</ProductID>
                <ProductID>FortiClientAndroid-5.2.3</ProductID>
                <ProductID>FortiClientAndroid-5.2.2</ProductID>
                <ProductID>FortiClientAndroid-5.2.1</ProductID>
                <ProductID>FortiClientAndroid-5.2.0</ProductID>
                <ProductID>FortiClientAndroid-5.0.3</ProductID>
                <ProductID>FortiClientAndroid-5.0.2</ProductID>
                <ProductID>FortiClientAndroid-5.0.1</ProductID>
                <ProductID>FortiClientAndroid-5.0.0</ProductID>
                <ProductID>FortiClientLinux-7.2.4</ProductID>
                <ProductID>FortiClientLinux-7.2.3</ProductID>
                <ProductID>FortiClientLinux-7.2.2</ProductID>
                <ProductID>FortiClientLinux-7.2.1</ProductID>
                <ProductID>FortiClientLinux-7.2.0</ProductID>
                <ProductID>FortiClientLinux-7.0.13</ProductID>
                <ProductID>FortiClientLinux-7.0.12</ProductID>
                <ProductID>FortiClientLinux-7.0.11</ProductID>
                <ProductID>FortiClientLinux-7.0.10</ProductID>
                <ProductID>FortiClientLinux-7.0.9</ProductID>
                <ProductID>FortiClientLinux-7.0.8</ProductID>
                <ProductID>FortiClientLinux-7.0.7</ProductID>
                <ProductID>FortiClientLinux-7.0.6</ProductID>
                <ProductID>FortiClientLinux-7.0.5</ProductID>
                <ProductID>FortiClientLinux-7.0.4</ProductID>
                <ProductID>FortiClientLinux-7.0.3</ProductID>
                <ProductID>FortiClientLinux-7.0.2</ProductID>
                <ProductID>FortiClientLinux-7.0.1</ProductID>
                <ProductID>FortiClientLinux-7.0.0</ProductID>
                <ProductID>FortiClientLinux-6.4.9</ProductID>
                <ProductID>FortiClientLinux-6.4.8</ProductID>
                <ProductID>FortiClientLinux-6.4.7</ProductID>
                <ProductID>FortiClientLinux-6.4.4</ProductID>
                <ProductID>FortiClientLinux-6.4.3</ProductID>
                <ProductID>FortiClientLinux-6.4.2</ProductID>
                <ProductID>FortiClientLinux-6.4.1</ProductID>
                <ProductID>FortiClientLinux-6.4.0</ProductID>
                <ProductID>FortiClientMac-7.2.4</ProductID>
                <ProductID>FortiClientMac-7.2.3</ProductID>
                <ProductID>FortiClientMac-7.2.2</ProductID>
                <ProductID>FortiClientMac-7.2.1</ProductID>
                <ProductID>FortiClientMac-7.2.0</ProductID>
                <ProductID>FortiClientMac-7.0.14</ProductID>
                <ProductID>FortiClientMac-7.0.13</ProductID>
                <ProductID>FortiClientMac-7.0.12</ProductID>
                <ProductID>FortiClientMac-7.0.11</ProductID>
                <ProductID>FortiClientMac-7.0.10</ProductID>
                <ProductID>FortiClientMac-7.0.9</ProductID>
                <ProductID>FortiClientMac-7.0.8</ProductID>
                <ProductID>FortiClientMac-7.0.7</ProductID>
                <ProductID>FortiClientMac-7.0.6</ProductID>
                <ProductID>FortiClientMac-7.0.5</ProductID>
                <ProductID>FortiClientMac-7.0.4</ProductID>
                <ProductID>FortiClientMac-7.0.3</ProductID>
                <ProductID>FortiClientMac-7.0.2</ProductID>
                <ProductID>FortiClientMac-7.0.1</ProductID>
                <ProductID>FortiClientMac-7.0.0</ProductID>
                <ProductID>FortiClientMac-6.4.10</ProductID>
                <ProductID>FortiClientMac-6.4.9</ProductID>
                <ProductID>FortiClientMac-6.4.8</ProductID>
                <ProductID>FortiClientMac-6.4.7</ProductID>
                <ProductID>FortiClientMac-6.4.6</ProductID>
                <ProductID>FortiClientMac-6.4.5</ProductID>
                <ProductID>FortiClientMac-6.4.4</ProductID>
                <ProductID>FortiClientMac-6.4.3</ProductID>
                <ProductID>FortiClientMac-6.4.2</ProductID>
                <ProductID>FortiClientMac-6.4.1</ProductID>
                <ProductID>FortiClientMac-6.4.0</ProductID>
                <ProductID>FortiClientWindows-7.0.7</ProductID>
                <ProductID>FortiClientWindows-7.0.6</ProductID>
                <ProductID>FortiClientWindows-7.0.5</ProductID>
                <ProductID>FortiClientWindows-7.0.4</ProductID>
                <ProductID>FortiClientWindows-7.0.3</ProductID>
                <ProductID>FortiClientWindows-7.0.2</ProductID>
                <ProductID>FortiClientWindows-7.0.1</ProductID>
                <ProductID>FortiClientWindows-7.0.0</ProductID>
                <ProductID>FortiClientWindows-6.4.10</ProductID>
                <ProductID>FortiClientWindows-6.4.9</ProductID>
                <ProductID>FortiClientWindows-6.4.8</ProductID>
                <ProductID>FortiClientWindows-6.4.7</ProductID>
                <ProductID>FortiClientWindows-6.4.6</ProductID>
                <ProductID>FortiClientWindows-6.4.5</ProductID>
                <ProductID>FortiClientWindows-6.4.4</ProductID>
                <ProductID>FortiClientWindows-6.4.3</ProductID>
                <ProductID>FortiClientWindows-6.4.2</ProductID>
                <ProductID>FortiClientWindows-6.4.1</ProductID>
                <ProductID>FortiClientWindows-6.4.0</ProductID>
                <ProductID>FortiClientiOS-7.0.6</ProductID>
                <ProductID>FortiClientiOS-7.0.5</ProductID>
                <ProductID>FortiClientiOS-7.0.4</ProductID>
                <ProductID>FortiClientiOS-7.0.3</ProductID>
                <ProductID>FortiClientiOS-7.0.1</ProductID>
                <ProductID>FortiClientiOS-7.0.0</ProductID>
                <ProductID>FortiClientiOS-6.0.1</ProductID>
                <ProductID>FortiClientiOS-6.0.0</ProductID>
                <ProductID>FortiClientiOS-5.6.6</ProductID>
                <ProductID>FortiClientiOS-5.6.5</ProductID>
                <ProductID>FortiClientiOS-5.6.1</ProductID>
                <ProductID>FortiClientiOS-5.6.0</ProductID>
                <ProductID>FortiClientiOS-5.4.4</ProductID>
                <ProductID>FortiClientiOS-5.4.3</ProductID>
                <ProductID>FortiClientiOS-5.4.1</ProductID>
                <ProductID>FortiClientiOS-5.4.0</ProductID>
                <ProductID>FortiClientiOS-5.2.3</ProductID>
                <ProductID>FortiClientiOS-5.2.2</ProductID>
                <ProductID>FortiClientiOS-5.2.1</ProductID>
                <ProductID>FortiClientiOS-5.2.0</ProductID>
                <ProductID>FortiClientiOS-5.0.3</ProductID>
                <ProductID>FortiClientiOS-5.0.2</ProductID>
                <ProductID>FortiClientiOS-5.0.1</ProductID>
                <ProductID>FortiClientiOS-5.0.0</ProductID>
                <ProductID>FortiClientiOS-4.0.2</ProductID>
                <ProductID>FortiClientiOS-4.0.1</ProductID>
                <ProductID>FortiClientiOS-4.0.0</ProductID>
                <ProductID>FortiClientiOS-2.0.1</ProductID>
                <ProductID>FortiClientiOS-2.0.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>4.6</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P/RL:U/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-22-230</URL>
                <Description>FortiClient(All) - Lack of client-side certificate validation using SAML SSO</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>