A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allows attacker to information disclosure via inspecting browser decrypted data
2021-12-09T09:15:06.867
2024-11-21T06:13:17.210
Modified
CVSSv3.1: 6.8 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | forticlient_enterprise_management_server | ≤ 6.4.4 | Yes |
Application | fortinet | forticlient_enterprise_management_server | 6.4.6 | Yes |
Application | fortinet | forticlient_enterprise_management_server | 7.0.0 | Yes |
Application | fortinet | forticlient_enterprise_management_server | 7.0.1 | Yes |