CVEFinder.io

CVE-2025-54660

đŸ”ļ medium
🔍 Scan for this CVE
Summary

An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a local attacker to run the application step by step and retrieve the saved VPN user password

CVSS Score
5.5
Medium
EPSS Score
0.0
Exploit Probability
Published Date
2025-11-18
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 32.6% of all 321,566 vulnerabilities in our database.

#216,619
Below average severity
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: Nov 18, 2025
🔍 Exploitation Status
None
No known exploits
âš™ī¸ Automatable
NO
Requires human interaction
đŸ’Ĩ Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2025-11-20
CVSS Vector 3.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 2

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-44278 â„šī¸ low 2.3 0.0 A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindo... 2026-05-12
CVE-2026-24018 âš ī¸ high 7.8 0.0 A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinu... 2026-03-10
CVE-2025-62676 âš ī¸ high 7.1 0.0 An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet Forti... 2026-02-10
CVE-2025-46373 âš ī¸ high 7.8 0.0 A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, F... 2025-11-18
CVE-2025-47761 âš ī¸ high 7.8 0.0 An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7... 2025-11-18
CVE-2025-31365 đŸ”ļ medium 5.8 0.0 An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.... 2025-10-14
These CVEs affect the same products