CVE-2021-22127: OS Command Injection
An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x before 6.2.9 may allow an unauthenticated attacker to execute arbitrary code on the host operating system as root via tricking the user into connecting to a network with a malicious name.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this FortiClient vulnerability?
The vulnerability ID is CVE-2021-22127.
What is the severity level of CVE-2021-22127?
The severity level of CVE-2021-22127 is high.
How does CVE-2021-22127 affect FortiClient for Linux?
CVE-2021-22127 affects FortiClient for Linux versions 6.4.x before 6.4.3 and 6.2.x before 6.2.9.
What is the impact of CVE-2021-22127?
CVE-2021-22127 allows an unauthenticated attacker to execute arbitrary code on the host operating system as root by tricking the user into connecting to a network with a malicious na.
Is there a fix available for CVE-2021-22127?
Yes, a fix is available. Users should update FortiClient for Linux to version 6.4.3 or later.