Lucene search

K
cveFortinetCVE-2021-43205
HistoryApr 06, 2022 - 10:15 a.m.

CVE-2021-43205

2022-04-0610:15:08
CWE-200
fortinet
web.nvd.nist.gov
61
cve-2021-43205
exposure of sensitive information
cwe-200
forticlient
linux
nvd
vulnerability

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.1

Confidence

High

EPSS

0.001

Percentile

33.2%

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and below and 6.2.9 and below may allow an unauthenticated attacker to access the confighandler webserver via external binaries.

Affected configurations

Nvd
Node
fortinetforticlientRange6.2.06.2.4linux
OR
fortinetforticlientRange6.2.66.2.9linux
OR
fortinetforticlientRange6.4.06.4.4linux
OR
fortinetforticlientRange7.0.07.0.2linux
OR
fortinetforticlientMatch6.4.7linux
VendorProductVersionCPE
fortinetforticlient*cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*
fortinetforticlient6.4.7cpe:2.3:a:fortinet:forticlient:6.4.7:*:*:*:*:linux:*:*

CNA Affected

[
  {
    "product": "Fortinet FortiClientLinux",
    "vendor": "Fortinet",
    "versions": [
      {
        "status": "affected",
        "version": "FortiClientLinux 7.0.2 and below,  6.4.7 and below, 6.2.9 and below"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.1

Confidence

High

EPSS

0.001

Percentile

33.2%

Related for CVE-2021-43205