First published: Thu Dec 09 2021(Updated: )
A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allows attacker to information disclosure via inspecting browser decrypted data
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiClient Enterprise Management Server | >=6.4.0<=6.4.4 | |
Fortinet FortiClient Enterprise Management Server | =6.4.6 | |
Fortinet FortiClient Enterprise Management Server | =7.0.0 | |
Fortinet FortiClient Enterprise Management Server | =7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36189 is a vulnerability in Fortinet FortiClientEMS versions 7.0.1 and below, as well as version 6.4.4 and below, that allows an attacker to perform information disclosure by inspecting browser decrypted data due to a missing encryption of sensitive data.
CVE-2021-36189 has a severity rating of 4.9, which is considered medium.
Fortinet FortiClientEMS versions 6.4.0 to 6.4.4, 7.0.0, and 7.0.1 are affected by CVE-2021-36189.
An attacker can exploit CVE-2021-36189 by inspecting browser decrypted data to gain unauthorized access to sensitive information.
Yes, it is recommended to update Fortinet FortiClientEMS to a version that is not affected by CVE-2021-36189.