SB2025040978 - Improper authentication in FortiClient for macOS
Published: April 9, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper authentication (CVE-ID: CVE-2024-52968)
The vulnerability allows an attacker to bypass authentication.
The vulnerability exists due to missing authentication in FortiMonitor Agent. An attacker with physical access to device can login to the system without a password as a standard user.
Remediation
Install update from vendor's website.