PSIRT Advisories

Multiple VPN applications insecurely store session cookies


The Missing Encryption Of Sensitive Data vulnerability in FortiClient may allow an attacker to access VPN session cookie from an endpoint device running FortiClient. The attacker can steal the cookies only if endpoint device has been compromised in such a way that the attacker has access to FortiClient's debug logs or memory space. Furthermore,  practical use of the stolen cookie requires the attacker to spoof the endpoint's IP address.

Affected Products

FortiClient for Windows (6.2.0 and earlier)
FortiClient for Mac OSX (6.2.0 and earlier)


Fortigate by default mitigates the session cookie misuse by verifying the source IP of client's request. As a precautionary measure, please upgrade to upcoming:
FortiClient for Windows 6.2.1
FortiClient for Mac OSX 6.2.1