{"api_version":"1","generated_at":"2026-07-23T10:58:56+00:00","cve":"CVE-2019-15711","urls":{"html":"https://cve.report/CVE-2019-15711","api":"https://cve.report/api/cve/CVE-2019-15711.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-15711","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-15711"},"summary":{"title":"CVE-2019-15711","description":"A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to run system commands under root privilege via injecting specially crafted \"ExportLogs\" type IPC client requests to the fctsched process.","state":"PUBLIC","assigner":"psirt@fortinet.com","published_at":"2020-02-06 16:15:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://danishcyberdefence.dk/blog/forticlient_linux","name":"https://danishcyberdefence.dk/blog/forticlient_linux","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Multiple privilege escalations in FortiClient for Linux | Danish Cyber Defence","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://fortiguard.com/psirt/FG-IR-19-238","name":"https://fortiguard.com/psirt/FG-IR-19-238","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Privilege escalation and DoS in FortiClient for Linux through local IPC socket | FortiGuard","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-15711","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-15711","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"15711","vulnerable":"1","versionEndIncluding":"6.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fortinet","cpe5":"forticlient","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"linux","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-15711","ASSIGNER":"psirt@fortinet.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Fortinet","product":{"product_data":[{"product_name":"Fortinet FortiClientLinux","version":{"version_data":[{"version_value":"FortiClientLinux 6.2.1 and below"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Escalation of privilege"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://fortiguard.com/psirt/FG-IR-19-238","url":"https://fortiguard.com/psirt/FG-IR-19-238"},{"refsource":"MISC","name":"https://danishcyberdefence.dk/blog/forticlient_linux","url":"https://danishcyberdefence.dk/blog/forticlient_linux"}]},"description":{"description_data":[{"lang":"eng","value":"A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to run system commands under root privilege via injecting specially crafted \"ExportLogs\" type IPC client requests to the fctsched process."}]}},"nvd":{"publishedDate":"2020-02-06 16:15:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*","versionEndIncluding":"6.2.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"15711","Ordinal":"155238","Title":"CVE-2019-15711","CVE":"CVE-2019-15711","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"15711","Ordinal":"1","NoteData":"A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to run system commands under root privilege via injecting specially crafted \"ExportLogs\" type IPC client requests to the fctsched process.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"15711","Ordinal":"2","NoteData":"2020-02-06","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"15711","Ordinal":"3","NoteData":"2020-02-07","Type":"Other","Title":"Modified"}]}}}