CVE-2021-36189: Medium severity fortinet forticlient ems cloud vulnerability
A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allows attacker to information disclosure via inspecting browser decrypted data
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-36189?
CVE-2021-36189 is a vulnerability in Fortinet FortiClientEMS versions 7.0.1 and below, as well as version 6.4.4 and below, that allows an attacker to perform information disclosure by inspecting browser decrypted data due to a missing encryption of sensitive data.
How severe is CVE-2021-36189?
CVE-2021-36189 has a severity rating of 4.9, which is considered medium.
Which software versions are affected by CVE-2021-36189?
Fortinet FortiClientEMS versions 6.4.0 to 6.4.4, 7.0.0, and 7.0.1 are affected by CVE-2021-36189.
How can an attacker exploit CVE-2021-36189?
An attacker can exploit CVE-2021-36189 by inspecting browser decrypted data to gain unauthorized access to sensitive information.
Is there a fix for CVE-2021-36189?
Yes, it is recommended to update Fortinet FortiClientEMS to a version that is not affected by CVE-2021-36189.