Show filters
87 Total Results
Displaying 31-40 of 87
Sort by:
Attacker Value
Unknown
CVE-2022-43946
Disclosure Date: April 11, 2023 (last updated October 08, 2023)
Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on the same file sharing network to execute commands via writing data into a windows pipe.
0
Attacker Value
Unknown
CVE-2022-42470
Disclosure Date: April 11, 2023 (last updated October 08, 2023)
A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe.
0
Attacker Value
Unknown
CVE-2022-40682
Disclosure Date: April 11, 2023 (last updated October 08, 2023)
A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe.
0
Attacker Value
Unknown
CVE-2022-33878
Disclosure Date: November 02, 2022 (last updated December 22, 2024)
An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiClient for Mac versions 7.0.0 through 7.0.5 may allow a local authenticated attacker to obtain the SSL-VPN password in cleartext via running a logstream for the FortiTray process in the terminal.
0
Attacker Value
Unknown
CVE-2022-26113
Disclosure Date: July 19, 2022 (last updated October 07, 2023)
An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.10 may allow a local attacker to perform an arbitrary file write on the system.
0
Attacker Value
Unknown
CVE-2021-41031
Disclosure Date: July 18, 2022 (last updated October 07, 2023)
A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior and 6.2.9 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for FortiESNAC service.
0
Attacker Value
Unknown
CVE-2021-43066
Disclosure Date: May 11, 2022 (last updated October 07, 2023)
A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below, version 6.2.9 and below, version 6.0.10 and below allows attacker to escalate privilege via the MSI installer.
0
Attacker Value
Unknown
CVE-2021-44167
Disclosure Date: May 11, 2022 (last updated October 07, 2023)
An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6.4.7 and below, 7.0.2 and below may allow an unauthenticated attacker to access sensitive information in log files and directories via symbolic links.
0
Attacker Value
Unknown
CVE-2021-22127
Disclosure Date: April 06, 2022 (last updated October 07, 2023)
An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x before 6.2.9 may allow an unauthenticated attacker to execute arbitrary code on the host operating system as root via tricking the user into connecting to a network with a malicious name.
0
Attacker Value
Unknown
CVE-2021-44169
Disclosure Date: April 06, 2022 (last updated October 07, 2023)
A improper initialization in Fortinet FortiClient (Windows) version 6.0.10 and below, version 6.2.9 and below, version 6.4.7 and below, version 7.0.3 and below allows attacker to gain administrative privileges via placing a malicious executable inside the FortiClient installer's directory.
0