QID 379144
Date Published: 2024-01-17
QID 379144: FortiClient Unauthorized Actor Vulnerability (FG-IR-21-226)
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux may allow an unauthenticated attacker to access the confighandler webserver via external binaries.
Affected Versions:
FortiClient for Linux version 7.0.2 and below
FortiClient for Linux version 6.4.7 and below
FortiClient for Linux version 6.2.9 to 6.2.0
QID Detection Logic (Authenticated) :
These checks for vulnerable version of FortiClient.
Successful exploitation of the vulnerability may allow an unauthenticated attacker to access the confighandler webserver via external binaries.
Solution
Vendor has released fix to address these vulnerabilities. Refer to FG-IR-21-226
Vendor References
- FG-IR-21-226 -
www.fortiguard.com/psirt/FG-IR-21-226
CVEs related to QID 379144
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-226 |
|