3.3
CVE-2023-37939
- EPSS 0.06%
- Published 10.10.2023 17:15:12
- Last modified 21.11.2024 08:12:30
- Source psirt@fortinet.com
- Teams watchlist Login
- Open Login
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions, Linux 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions and Mac 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions, 6.2 all versions, may allow a local authenticated attacker with no Administrative privileges to retrieve the list of files or folders excluded from malware scanning.
Data is provided by the National Vulnerability Database (NVD)
Fortinet ≫ FortiClient SwPlatformlinux Version >= 6.2.0 <= 6.2.9
Fortinet ≫ FortiClient SwPlatformmacos Version >= 6.2.0 <= 6.2.9
Fortinet ≫ FortiClient SwPlatformwindows Version >= 6.2.0 <= 6.2.9
Fortinet ≫ FortiClient SwPlatformlinux Version >= 6.4.0 <= 6.4.9
Fortinet ≫ FortiClient SwPlatformmacos Version >= 6.4.0 <= 6.4.10
Fortinet ≫ FortiClient SwPlatformwindows Version >= 6.4.0 <= 6.4.10
Fortinet ≫ FortiClient SwPlatformlinux Version >= 7.0.0 <= 7.0.9
Fortinet ≫ FortiClient SwPlatformmacos Version >= 7.0.0 <= 7.0.9
Fortinet ≫ FortiClient SwPlatformwindows Version >= 7.0.0 <= 7.0.9
Fortinet ≫ FortiClient Version7.2.0 SwPlatformlinux
Fortinet ≫ FortiClient Version7.2.0 SwPlatformmacos
Fortinet ≫ FortiClient Version7.2.0 SwPlatformwindows
Fortinet ≫ FortiClient Version7.2.1 SwPlatformmacos
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.186 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
psirt@fortinet.com | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.