CVE-2023-41840
- EPSS 0.07%
- Veröffentlicht 14.11.2023 18:15:53
- Zuletzt bearbeitet 21.11.2024 08:21:46
A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path.
CVE-2023-33304
- EPSS 0%
- Veröffentlicht 14.11.2023 18:15:30
- Zuletzt bearbeitet 21.11.2024 08:05:22
A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system protections via the use of static credentials.
CVE-2023-37939
- EPSS 0.06%
- Veröffentlicht 10.10.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 08:12:30
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions, Linux 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions and Mac 7....
CVE-2022-33877
- EPSS 0.03%
- Veröffentlicht 13.06.2023 09:15:14
- Zuletzt bearbeitet 21.11.2024 07:08:30
An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authent...
CVE-2023-22635
- EPSS 0.04%
- Veröffentlicht 11.04.2023 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:45:05
A download of code without Integrity check vulnerability [CWE-494] in FortiClientMac version 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions, 5.6 all versions, 5.4 all versions, 5.2 all versions, 5.0 all versions and 4.0 al...
CVE-2022-42470
- EPSS 0.1%
- Veröffentlicht 11.04.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:25:01
A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pip...
CVE-2022-40682
- EPSS 0.05%
- Veröffentlicht 11.04.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:21:50
A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe.
CVE-2022-43946
- EPSS 0.14%
- Veröffentlicht 11.04.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:27:23
Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows att...
CVE-2022-33878
- EPSS 0.06%
- Veröffentlicht 02.11.2022 12:15:53
- Zuletzt bearbeitet 21.11.2024 07:08:30
An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiClient for Mac versions 7.0.0 through 7.0.5 may allow a local authenticated attacker to obtain the SSL-VPN password in cleartext via running a logstream for...
CVE-2022-26113
- EPSS 0.11%
- Veröffentlicht 19.07.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:53:27
An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.10 may allow a local attacker to perform an arbitrary file write on the system.