An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and below and 6.2.9 and below may allow an unauthenticated attacker to access the confighandler webserver via external binaries.
2022-04-06T10:15:08.037
2024-11-21T06:28:50.620
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | forticlient | ≤ 6.2.4 | Yes |
Application | fortinet | forticlient | ≤ 6.2.9 | Yes |
Application | fortinet | forticlient | ≤ 6.4.4 | Yes |
Application | fortinet | forticlient | ≤ 7.0.2 | Yes |
Application | fortinet | forticlient | 6.4.7 | Yes |