Description
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and below and 6.2.9 and below may allow an unauthenticated attacker to access the confighandler webserver via external binaries.
CVSS breakdown
CVSS 3.1
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
E
X
RL
W
RC
Changed
Affected products
- fortinet / Fortinet FortiClientLinuxFortiClientLinux 7.0.2 and below, 6.4.7 and below, 6.2.9 and below – FortiClientLinux 7.0.2 and below, 6.4.7 and below, 6.2.9 and below
References
- VENDOR_ADVISORYhttps://fortiguard.com/psirt/FG-IR-21-226