Lucene search

K
cveFortinetCVE-2017-7344
HistoryDec 14, 2017 - 6:29 p.m.

CVE-2017-7344

2017-12-1418:29:00
fortinet
web.nvd.nist.gov
45
cve-2017-7344
fortinet
forticlient
privilege escalation
windows
vpn
security alert
certificate chain

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.009

Percentile

82.6%

A privilege escalation in Fortinet FortiClient Windows 5.4.3 and earlier as well as 5.6.0 allows attacker to gain privilege via exploiting the Windows “security alert” dialog thereby popping up when the “VPN before logon” feature is enabled and an untrusted certificate chain.

Affected configurations

Nvd
Node
fortinetforticlientRange5.4.3windows
OR
fortinetforticlientMatch5.6.0windows
VendorProductVersionCPE
fortinetforticlient*cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*
fortinetforticlient5.6.0cpe:2.3:a:fortinet:forticlient:5.6.0:*:*:*:*:windows:*:*

CNA Affected

[
  {
    "product": "FortiClientWindows",
    "vendor": "Fortinet, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "5.6.0, 5.4.3, 5.4.2, 5.4.1, 5.4.0"
      }
    ]
  }
]

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.009

Percentile

82.6%

Related for CVE-2017-7344