{"api_version":"1","generated_at":"2026-07-23T11:19:49+00:00","cve":"CVE-2019-16152","urls":{"html":"https://cve.report/CVE-2019-16152","api":"https://cve.report/api/cve/CVE-2019-16152.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-16152","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-16152"},"summary":{"title":"CVE-2019-16152","description":"A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to cause FortiClient processes running under root privilege crashes via sending specially crafted IPC client requests to the fctsched process due the nanomsg not been correctly validated.","state":"PUBLIC","assigner":"psirt@fortinet.com","published_at":"2020-02-06 16:15:00","updated_at":"2020-02-12 18:35:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://danishcyberdefence.dk/blog/forticlient_linux","name":"https://danishcyberdefence.dk/blog/forticlient_linux","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Multiple privilege escalations in FortiClient for Linux | Danish Cyber Defence","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://fortiguard.com/psirt/FG-IR-19-238","name":"https://fortiguard.com/psirt/FG-IR-19-238","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Privilege escalation and DoS in FortiClient for Linux through local IPC socket | FortiGuard","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-16152","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16152","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"16152","vulnerable":"1","versionEndIncluding":"6.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fortinet","cpe5":"forticlient","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"linux","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-16152","ASSIGNER":"psirt@fortinet.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Fortinet","product":{"product_data":[{"product_name":"Fortinet FortiClientLinux","version":{"version_data":[{"version_value":"FortiClientLinux 6.2.1 and below"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Escalation of privilege"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://fortiguard.com/psirt/FG-IR-19-238","url":"https://fortiguard.com/psirt/FG-IR-19-238"},{"refsource":"MISC","name":"https://danishcyberdefence.dk/blog/forticlient_linux","url":"https://danishcyberdefence.dk/blog/forticlient_linux"}]},"description":{"description_data":[{"lang":"eng","value":"A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to cause FortiClient processes running under root privilege crashes via sending specially crafted IPC client requests to the fctsched process due the nanomsg not been correctly validated."}]}},"nvd":{"publishedDate":"2020-02-06 16:15:00","lastModifiedDate":"2020-02-12 18:35:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*","versionEndIncluding":"6.2.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"16152","Ordinal":"155726","Title":"CVE-2019-16152","CVE":"CVE-2019-16152","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"16152","Ordinal":"1","NoteData":"A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to cause FortiClient processes running under root privilege crashes via sending specially crafted IPC client requests to the fctsched process due the nanomsg not been correctly validated.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"16152","Ordinal":"2","NoteData":"2020-02-06","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"16152","Ordinal":"3","NoteData":"2020-02-07","Type":"Other","Title":"Modified"}]}}}