Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
cmartinson
New Contributor

FortiClient 5.6.0.1075 Vulnerability Scan detects issues in Chrome I cannot fix

I recently installed FortiClient 5.6.0.1075 and ran the Vulnerability Scan. It detected 162 vulnerabilities, all having to do with Google Chrome 49.0.2618.8 and suggests that I patch the software manually since it cannot be auto-patched.

 

Two problems: One is that I only have Chrome version 61.0.3163.100 installed (as far as I know), and the other is that re-installs of Chrome and re-scans by the FortiClient Vulnerability Scan return the same results.

 

Has anyone run into this? Is it possible I'm running into conflicts with other antivirus/antimalware software I have running?

5 REPLIES 5
timmertc
New Contributor

I have the same problem, but with Client 6.0.0 & 6.0.1

I had both Chrome and Vivaldi installed (Vivaldi uses Chromium backend). I uninstalled Chrome, scanned, still had the vulnerabilities. Uninstalled Vivaldi, scanned, still had the vulnerabilities.

I then deleted the Chrome installation folder, found the Google folder in the hidden AppData folder, deleted it, then reran the scan. Result: Still have Chrome vulnerabilities. I tried to find the same folders for Vivaldi, but it appears to clean up after itself much better than Chrome.

 

So I have 61 Critical, 316 High, 412 Medium, and 5 Low vulnerabilities, all Chrome vulnerabilities, that I can't patch  or get rid of.

 

pavol_jaco
New Contributor II

I have the same problem, all PC are becoming not compliant and therefore are blocked. That is huge problem in production environment. Looks like I cannot rely on forticlient vulnerability modul. Also there is no notification in windows environment about vulnerabilities found. Even I have set 15 days grace period for patching vulnerabilities, nobody noticed that. Any idea how to fix this?

tanr
Valued Contributor II

I would open a support ticket with TAC for this.

 

If updating Chrome on the systems doesn't fix the report it may be that you have some third party software installed that is using an outdated version of Chrome/Chromium as a backend.

pavol_jaco
New Contributor II

I have noticed, that only some PCs are affected with this "bug". Only specific version of Windows OS 10 (version 1709). Other PCs (with older version 1607) has no problem, even they have same software installed.

Forticlient is showing more than 700 vulnerabilities, all for Chrome browser. I think, this version of chrome (68) is not even affected with those vulnerabilities. I have tried to uninstall it, but no change.

I am going to open a ticket, but that is time consuming. I was hoping, that somebody else already figure-it out.

pavol_jaco

I have opened ticket for this. According to TAC, it is a know bug (id 0467328) and it should be resolved in version 6.0.2. But, I have tried it. Even version 6.0.3. And some PC still have same problem. Waiting for TAC replay...

Labels
Top Kudoed Authors