FortiClient and EMS
CVE-2024-54019: Improper validation of certificate with host mismatch in FortiClientWindows
A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| FortiClientWindows 7.4 | 7.4.1 or later |
| FortiClientWindows 7.2.0 to 7.2.6 | 7.2.7 or later |
| FortiClientWindows 7.0.0 to 7.0.14 | Upgrade past 7.0.14; see the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.