QID 379144

Date Published: 2024-01-17

QID 379144: FortiClient Unauthorized Actor Vulnerability (FG-IR-21-226)

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux may allow an unauthenticated attacker to access the confighandler webserver via external binaries.
Affected Versions:
FortiClient for Linux version 7.0.2 and below
FortiClient for Linux version 6.4.7 and below
FortiClient for Linux version 6.2.9 to 6.2.0

QID Detection Logic (Authenticated) :
These checks for vulnerable version of FortiClient.

Successful exploitation of the vulnerability may allow an unauthenticated attacker to access the confighandler webserver via external binaries.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Vendor has released fix to address these vulnerabilities. Refer to FG-IR-21-226
    Vendor References

    CVEs related to QID 379144

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-21-226 URL Logo www.fortiguard.com/psirt/FG-IR-21-226