CVE-2024-54019
Last modified
CVE-2024-54019 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Forticlient | >= 7.0.0, < 7.2.7 |
| Fortinet | Forticlient | 7.4.0 |
References
- https://fortiguard.fortinet.com/psirt/FG-IR-24-365Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-54019?
How severe is CVE-2024-54019?
How do I fix CVE-2024-54019?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-54013Penetration Testing engineers at Amazon have identified a se…8.8
- CVE-2024-54014Improper authorization in handler for custom URL scheme issu…3.6
- CVE-2024-54015A vulnerability has been identified in SIPROTEC 5 6MD84 (CP3…8.7
- CVE-2024-54016Improper Handling of Highly Compressed Data (Data Amplificat…4.3
- CVE-2024-54017A vulnerability has been identified in SIPROTEC 5 6MD84 (CP3…6.9
- CVE-2024-54018Multiple improper neutralization of special elements used in…7.2
- CVE-2024-5402Unquoted Search Path or Element vulnerability in ABB Mint Wo…7.8
- CVE-2024-54020A missing authorization in Fortinet FortiManager versions 7.…4.3
- CVE-2024-54021An Improper Neutralization of CRLF Sequences in HTTP Headers…5.8
- CVE-2024-54024An improper neutralization of special elements used in an OS…7.2
- CVE-2024-54025An improper neutralization of special elements used in an OS…6.7
- CVE-2024-54026An improper neutralization of special elements used in an sq…8.8
Are you affected by CVE-2024-54019?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
