7
CVE-2022-33877
- EPSS 0.03%
- Veröffentlicht 13.06.2023 09:15:14
- Zuletzt bearbeitet 21.11.2024 07:08:30
- Quelle psirt@fortinet.com
- Teams Watchlist Login
- Unerledigt Login
An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated attacker to tamper with files in the installation folder, if FortiClient or FortiConverter is installed in an insecure folder.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ FortiClient SwPlatformwindows Version >= 6.4.0 <= 6.4.8
Fortinet ≫ FortiClient SwPlatformwindows Version >= 7.0.0 <= 7.0.6
Fortinet ≫ Forticonverter SwPlatformwindows Version >= 6.0.0 <= 6.0.3
Fortinet ≫ Forticonverter Version6.2.0 SwPlatformwindows
Fortinet ≫ Forticonverter Version6.2.1 SwPlatformwindows
Fortinet ≫ Forticonverter Version7.0.0 SwPlatformwindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.063 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
psirt@fortinet.com | 7 | 1 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.