CVE-2021-41028: High severity fortinet forticlient vulnerability
A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 and below, 6.4.6 and below may allow an unauthenticated and network adjacent attacker to perform a man-in-the-middle attack between the EMS and the FCT via the telemetry protocol.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-41028.
What software products are affected by this vulnerability?
FortiClientEMS 7.0.1 and below, 6.4.6 and below, FortiClientWindows, FortiClientLinux, and FortiClientMac 7.0.1 and below, 6.4.6 and below.
What is the severity of CVE-2021-41028?
The severity of CVE-2021-41028 is high.
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The CWE ID for this vulnerability is CWE-321 and CWE-297.
How can I fix this vulnerability?
To fix this vulnerability, update FortiClientEMS, FortiClientWindows, FortiClientLinux, and FortiClientMac to versions higher than 7.0.1 or 6.4.6.