PSIRT Advisory

Console window of FortiClient for Mac OS displays password in clear-text.

Summary

A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker  to read sensitive information logged in the console window when the user connects to an SSL VPN Gateway.

Impact

Information Disclosure

Affected Products

FortiClient for Mac OS version 6.2.0 and below. 

FortiClient for Mac OS version 6.0.7 and below.

Solutions

Please upgrade to FortiClient for Mac OS version 6.2.1 and above. 

Please upgrade to FortiClient for Mac OS version 6.0.8  and above.

Acknowledgement

Fortinet is pleased to thank Raymond Lopez and Mihai Florea for reporting this issue under responsible disclosure and for helping us make our products more secure.