CVE-2021-43205

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and below and 6.2.9 and below may allow an unauthenticated attacker to access the confighandler webserver via external binaries.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-21-226 Patch Vendor Advisory
https://fortiguard.com/psirt/FG-IR-21-226 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*
cpe:2.3:a:fortinet:forticlient:6.4.7:*:*:*:*:linux:*:*

History

21 Nov 2024, 06:28

Type Values Removed Values Added
References () https://fortiguard.com/psirt/FG-IR-21-226 - Patch, Vendor Advisory () https://fortiguard.com/psirt/FG-IR-21-226 - Patch, Vendor Advisory
CVSS v2 : 5.0
v3 : 5.3
v2 : 5.0
v3 : 4.3

Information

Published : 2022-04-06 10:15

Updated : 2024-11-21 06:28


NVD link : CVE-2021-43205

Mitre link : CVE-2021-43205

CVE.ORG link : CVE-2021-43205


JSON object : View

Products Affected

fortinet

  • forticlient
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor