Show filters
87 Total Results
Displaying 41-50 of 87
Sort by:
Attacker Value
Unknown

CVE-2021-43205

Disclosure Date: April 06, 2022 (last updated February 23, 2025)
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and below and 6.2.9 and below may allow an unauthenticated attacker to access the confighandler webserver via external binaries.
Attacker Value
Unknown

CVE-2021-41028

Disclosure Date: December 16, 2021 (last updated February 23, 2025)
A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 and below, 6.4.6 and below may allow an unauthenticated and network adjacent attacker to perform a man-in-the-middle attack between the EMS and the FCT via the telemetry protocol.
Attacker Value
Unknown

CVE-2021-36167

Disclosure Date: December 09, 2021 (last updated February 23, 2025)
An improper authorization vulnerabiltiy [CWE-285] in FortiClient Windows versions 7.0.0 and 6.4.6 and below and 6.2.8 and below may allow an unauthenticated attacker to bypass the webfilter control via modifying the session-id paramater.
Attacker Value
Unknown

CVE-2021-43204

Disclosure Date: December 09, 2021 (last updated February 23, 2025)
A improper control of a resource through its lifetime in Fortinet FortiClientWindows version 6.4.1 and 6.4.0, version 6.2.9 and below, version 6.0.10 and below allows attacker to cause a complete denial of service of its components via changes of directory access permissions.
Attacker Value
Unknown

CVE-2021-36189

Disclosure Date: December 09, 2021 (last updated February 23, 2025)
A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allows attacker to information disclosure via inspecting browser decrypted data
Attacker Value
Unknown

CVE-2021-41030

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4 and below may allow an unauthenticated attacker to impersonate an existing user by intercepting and re-using valid SAML authentication messages.
Attacker Value
Unknown

CVE-2021-32592

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x may allow an attacker to perform a DLL Hijack attack on affected devices via a malicious OpenSSL engine library in the search path.
Attacker Value
Unknown

CVE-2021-36183

Disclosure Date: November 02, 2021 (last updated February 23, 2025)
An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.
Attacker Value
Unknown

CVE-2021-42754

Disclosure Date: November 02, 2021 (last updated February 23, 2025)
An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authenticated attacker to hijack the MacOS camera without the user permission via the malicious dylib file.
Attacker Value
Unknown

CVE-2020-15940

Disclosure Date: November 02, 2021 (last updated February 23, 2025)
An improper neutralization of input vulnerability [CWE-79] in FortiClientEMS versions 6.4.1 and below and 6.2.9 and below may allow a remote authenticated attacker to inject malicious script/tags via the name parameter of various sections of the server.