CVE-2021-36167: Medium severity fortinet forticlient ssl vpn vulnerability
Published Dec 9, 2021
·Updated
An improper authorization vulnerabiltiy [CWE-285] in FortiClient Windows versions 7.0.0 and 6.4.6 and below and 6.2.8 and below may allow an unauthenticated attacker to bypass the webfilter control via modifying the session-id paramater.
Affected Software
3 affected components
Fortinet FortiClient Windows>=6.4.0<=6.4.6
Fortinet FortiClient Windows=6.2.7
Fortinet FortiClient Windows=7.0.0
Remediation
Patch Available
Event History
Dec 9, 2021
CVE Published
via MITRE·09:33 AM
Data Sourced
via MITRE·09:33 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-36167.
2
What is the severity rating of CVE-2021-36167?
CVE-2021-36167 has a severity rating of 5.3, which is considered medium.
3
Which versions of FortiClient Windows are affected by CVE-2021-36167?
FortiClient Windows versions 7.0.0, 6.4.6 and below, and 6.2.8 and below are affected by CVE-2021-36167.
4
How can an attacker exploit CVE-2021-36167?
An unauthenticated attacker can exploit CVE-2021-36167 by modifying the session-id parameter to bypass the webfilter control in FortiClient Windows.
5
Is there a fix available for CVE-2021-36167?
Yes, Fortinet has released patches to address the vulnerability. It is recommended to update FortiClient Windows to the latest version.