SB2025040978 - Improper authentication in FortiClient for macOS



SB2025040978 - Improper authentication in FortiClient for macOS

Published: April 9, 2025

Security Bulletin ID SB2025040978
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper authentication (CVE-ID: CVE-2024-52968)

The vulnerability allows an attacker to bypass authentication.

The vulnerability exists due to missing authentication in FortiMonitor Agent. An attacker with physical access to device can login to the system without a password as a standard user.


Remediation

Install update from vendor's website.