- EPSS 0.29%
- Veröffentlicht 10.09.2024 15:15:14
- Zuletzt bearbeitet 25.09.2024 18:36:45
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8, 1.2.1 through 1.2.5 allows ...
CVE-2023-47534
- EPSS 0.25%
- Veröffentlicht 12.03.2024 15:15:46
- Zuletzt bearbeitet 21.11.2024 08:30:24
A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or co...
CVE-2021-44172
- EPSS 0.47%
- Veröffentlicht 13.09.2023 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:30:30
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 through 7.0.7, in all 6.4 and 6.2 version management interface may allow an unauthenticated attacker to gain i...
CVE-2021-41028
- EPSS 0.14%
- Veröffentlicht 16.12.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:25:18
A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMa...
CVE-2020-15941
- EPSS 1.12%
- Veröffentlicht 06.10.2021 10:15:07
- Zuletzt bearbeitet 21.11.2024 05:06:30
A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authenticated attacker to inject directory traversal character sequences to add/delete the files of the server via the name parameter of ...
CVE-2021-24019
- EPSS 15.19%
- Veröffentlicht 06.10.2021 10:15:07
- Zuletzt bearbeitet 21.11.2024 05:52:13
An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtai...