Fortinet

FortiClient

73 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 18.07.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:25:18

A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior and 6.2.9 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible fo...

  • EPSS 0.06%
  • Veröffentlicht 11.05.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:28:37

A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below, version 6.2.9 and below, version 6.0.10 and below allows attacker to escalate privilege via the MSI installer.

  • EPSS 0.24%
  • Veröffentlicht 11.05.2022 15:15:08
  • Zuletzt bearbeitet 21.11.2024 06:30:29

An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6.4.7 and below, 7.0.2 and below may allow an unauthenticated attacker to access sensitive information...

  • EPSS 0.31%
  • Veröffentlicht 06.04.2022 16:15:07
  • Zuletzt bearbeitet 21.11.2024 05:49:33

An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x before 6.2.9 may allow an unauthenticated attacker to execute arbitrary code on the host operating system as root via tricking the use...

  • EPSS 0.15%
  • Veröffentlicht 06.04.2022 10:15:08
  • Zuletzt bearbeitet 21.11.2024 06:30:29

A improper initialization in Fortinet FortiClient (Windows) version 6.0.10 and below, version 6.2.9 and below, version 6.4.7 and below, version 7.0.3 and below allows attacker to gain administrative privileges via placing a malicious executable insid...

  • EPSS 0.6%
  • Veröffentlicht 06.04.2022 10:15:08
  • Zuletzt bearbeitet 21.11.2024 06:28:50

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and below and 6.2.9 and below may allow an unauthenticated attacker to access the confighandler webserver vi...

  • EPSS 0.14%
  • Veröffentlicht 16.12.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:25:18

A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMa...

  • EPSS 0.14%
  • Veröffentlicht 09.12.2021 10:15:11
  • Zuletzt bearbeitet 21.11.2024 06:13:14

An improper authorization vulnerabiltiy [CWE-285] in FortiClient Windows versions 7.0.0 and 6.4.6 and below and 6.2.8 and below may allow an unauthenticated attacker to bypass the webfilter control via modifying the session-id paramater.

  • EPSS 0.05%
  • Veröffentlicht 09.12.2021 09:15:07
  • Zuletzt bearbeitet 21.11.2024 06:28:50

A improper control of a resource through its lifetime in Fortinet FortiClientWindows version 6.4.1 and 6.4.0, version 6.2.9 and below, version 6.0.10 and below allows attacker to cause a complete denial of service of its components via changes of dir...

  • EPSS 0.05%
  • Veröffentlicht 01.12.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:07:20

An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x may allow an attacker to perform a DLL Hijack attack on affected devices via a malicious OpenSSL en...