<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Credentials can be dumped from memory</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-23-278</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2024-12-18T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2024-12-18T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2025-04-22T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClient Windows and FortiClient Linux may permit a local authenticated user to retrieve VPN password via memory dump, due to JavaScript&#39;s garbage collector
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Information disclosure
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="4">
            None
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:DocumentReferences>
        <cvrf:Reference>
            <cvrf:URL>https://fortiguard.fortinet.com/psirt/FG-IR-23-278</cvrf:URL>
            <cvrf:Description>Credentials can be dumped from memory</cvrf:Description>
        </cvrf:Reference>
        <cvrf:Reference>
            <cvrf:URL>https://docs.fortinet.com/document/forticlient/7.4.1/xml-reference-guide/56173</cvrf:URL>
            <cvrf:Description>https://docs.fortinet.com/document/forticlient/7.4.1/xml-reference-guide/56173</cvrf:Description>
        </cvrf:Reference>
        <cvrf:Reference>
            <cvrf:URL>https://docs.fortinet.com/document/forticlient/7.4.1/ems-administration-guide/682498/remote-access</cvrf:URL>
            <cvrf:Description>https://docs.fortinet.com/document/forticlient/7.4.1/ems-administration-guide/682498/remote-access</cvrf:Description>
        </cvrf:Reference>
    </cvrf:DocumentReferences>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Fortinet is pleased to thank Efstratios Chatzoglou, Vyron Kampourakis, Zisis Tsiatsikas, Georgios Karopoulos, and Georgios Kambourakis from the University of the Aegean and the Norwegian University of Science and Technology, and Hassan Al-Khafaji from NourNet for reporting this vulnerability under responsible disclosure.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiClientLinux" Type="Product Name">
                <Branch Name="7.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.4.2">FortiClientLinux 7.4.2</FullProductName>
                </Branch>
                <Branch Name="7.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.4.1">FortiClientLinux 7.4.1</FullProductName>
                </Branch>
                <Branch Name="7.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.4.0">FortiClientLinux 7.4.0</FullProductName>
                </Branch>
                <Branch Name="7.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.7">FortiClientLinux 7.2.7</FullProductName>
                </Branch>
                <Branch Name="7.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.6">FortiClientLinux 7.2.6</FullProductName>
                </Branch>
                <Branch Name="7.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.5">FortiClientLinux 7.2.5</FullProductName>
                </Branch>
                <Branch Name="7.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.4">FortiClientLinux 7.2.4</FullProductName>
                </Branch>
                <Branch Name="7.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.3">FortiClientLinux 7.2.3</FullProductName>
                </Branch>
                <Branch Name="7.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.2">FortiClientLinux 7.2.2</FullProductName>
                </Branch>
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.1">FortiClientLinux 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.2.0">FortiClientLinux 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.13" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.13">FortiClientLinux 7.0.13</FullProductName>
                </Branch>
                <Branch Name="7.0.12" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.12">FortiClientLinux 7.0.12</FullProductName>
                </Branch>
                <Branch Name="7.0.11" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.11">FortiClientLinux 7.0.11</FullProductName>
                </Branch>
                <Branch Name="7.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.10">FortiClientLinux 7.0.10</FullProductName>
                </Branch>
                <Branch Name="7.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.9">FortiClientLinux 7.0.9</FullProductName>
                </Branch>
                <Branch Name="7.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.8">FortiClientLinux 7.0.8</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.7">FortiClientLinux 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.6">FortiClientLinux 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.5">FortiClientLinux 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.4">FortiClientLinux 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.3">FortiClientLinux 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.2">FortiClientLinux 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.1">FortiClientLinux 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientLinux-7.0.0">FortiClientLinux 7.0.0</FullProductName>
                </Branch>
            </Branch>
            <Branch Name="FortiClientWindows" Type="Product Name">
                <Branch Name="7.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.4.1">FortiClientWindows 7.4.1</FullProductName>
                </Branch>
                <Branch Name="7.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.4.0">FortiClientWindows 7.4.0</FullProductName>
                </Branch>
                <Branch Name="7.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.2.6">FortiClientWindows 7.2.6</FullProductName>
                </Branch>
                <Branch Name="7.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.2.5">FortiClientWindows 7.2.5</FullProductName>
                </Branch>
                <Branch Name="7.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.2.4">FortiClientWindows 7.2.4</FullProductName>
                </Branch>
                <Branch Name="7.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.2.3">FortiClientWindows 7.2.3</FullProductName>
                </Branch>
                <Branch Name="7.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.2.2">FortiClientWindows 7.2.2</FullProductName>
                </Branch>
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.2.1">FortiClientWindows 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.2.0">FortiClientWindows 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.13" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.13">FortiClientWindows 7.0.13</FullProductName>
                </Branch>
                <Branch Name="7.0.12" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.12">FortiClientWindows 7.0.12</FullProductName>
                </Branch>
                <Branch Name="7.0.11" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.11">FortiClientWindows 7.0.11</FullProductName>
                </Branch>
                <Branch Name="7.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.10">FortiClientWindows 7.0.10</FullProductName>
                </Branch>
                <Branch Name="7.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.9">FortiClientWindows 7.0.9</FullProductName>
                </Branch>
                <Branch Name="7.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.8">FortiClientWindows 7.0.8</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.7">FortiClientWindows 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.6">FortiClientWindows 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.5">FortiClientWindows 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.4">FortiClientWindows 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.3">FortiClientWindows 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.2">FortiClientWindows 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.1">FortiClientWindows 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiClientWindows-7.0.0">FortiClientWindows 7.0.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Credentials can be dumped from memory</Title>
        <cvrf:CVE>CVE-2024-50570</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiClientLinux-7.4.2</ProductID>
                <ProductID>FortiClientLinux-7.4.1</ProductID>
                <ProductID>FortiClientLinux-7.4.0</ProductID>
                <ProductID>FortiClientLinux-7.2.7</ProductID>
                <ProductID>FortiClientLinux-7.2.6</ProductID>
                <ProductID>FortiClientLinux-7.2.5</ProductID>
                <ProductID>FortiClientLinux-7.2.4</ProductID>
                <ProductID>FortiClientLinux-7.2.3</ProductID>
                <ProductID>FortiClientLinux-7.2.2</ProductID>
                <ProductID>FortiClientLinux-7.2.1</ProductID>
                <ProductID>FortiClientLinux-7.2.0</ProductID>
                <ProductID>FortiClientLinux-7.0.13</ProductID>
                <ProductID>FortiClientLinux-7.0.12</ProductID>
                <ProductID>FortiClientLinux-7.0.11</ProductID>
                <ProductID>FortiClientLinux-7.0.10</ProductID>
                <ProductID>FortiClientLinux-7.0.9</ProductID>
                <ProductID>FortiClientLinux-7.0.8</ProductID>
                <ProductID>FortiClientLinux-7.0.7</ProductID>
                <ProductID>FortiClientLinux-7.0.6</ProductID>
                <ProductID>FortiClientLinux-7.0.5</ProductID>
                <ProductID>FortiClientLinux-7.0.4</ProductID>
                <ProductID>FortiClientLinux-7.0.3</ProductID>
                <ProductID>FortiClientLinux-7.0.2</ProductID>
                <ProductID>FortiClientLinux-7.0.1</ProductID>
                <ProductID>FortiClientLinux-7.0.0</ProductID>
                <ProductID>FortiClientWindows-7.4.1</ProductID>
                <ProductID>FortiClientWindows-7.4.0</ProductID>
                <ProductID>FortiClientWindows-7.2.6</ProductID>
                <ProductID>FortiClientWindows-7.2.5</ProductID>
                <ProductID>FortiClientWindows-7.2.4</ProductID>
                <ProductID>FortiClientWindows-7.2.3</ProductID>
                <ProductID>FortiClientWindows-7.2.2</ProductID>
                <ProductID>FortiClientWindows-7.2.1</ProductID>
                <ProductID>FortiClientWindows-7.2.0</ProductID>
                <ProductID>FortiClientWindows-7.0.13</ProductID>
                <ProductID>FortiClientWindows-7.0.12</ProductID>
                <ProductID>FortiClientWindows-7.0.11</ProductID>
                <ProductID>FortiClientWindows-7.0.10</ProductID>
                <ProductID>FortiClientWindows-7.0.9</ProductID>
                <ProductID>FortiClientWindows-7.0.8</ProductID>
                <ProductID>FortiClientWindows-7.0.7</ProductID>
                <ProductID>FortiClientWindows-7.0.6</ProductID>
                <ProductID>FortiClientWindows-7.0.5</ProductID>
                <ProductID>FortiClientWindows-7.0.4</ProductID>
                <ProductID>FortiClientWindows-7.0.3</ProductID>
                <ProductID>FortiClientWindows-7.0.2</ProductID>
                <ProductID>FortiClientWindows-7.0.1</ProductID>
                <ProductID>FortiClientWindows-7.0.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>4.9</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N/E:F/RL:X/RC:X</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-23-278</URL>
                <Description>Credentials can be dumped from memory</Description>
            </Reference>Reference>
            <Reference>
                <URL>https://docs.fortinet.com/document/forticlient/7.4.1/xml-reference-guide/56173</URL>
                <Description>https://docs.fortinet.com/document/forticlient/7.4.1/xml-reference-guide/56173</Description>
            </Reference>
            <Reference>
                <URL>https://docs.fortinet.com/document/forticlient/7.4.1/ems-administration-guide/682498/remote-access</URL>
                <Description>https://docs.fortinet.com/document/forticlient/7.4.1/ems-administration-guide/682498/remote-access</Description>
            </Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>