CVE-2021-43205: Infoleak
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and below and 6.2.9 and below may allow an unauthenticated attacker to access the confighandler webserver via external binaries.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-43205?
CVE-2021-43205 is a vulnerability in FortiClient for Linux versions 7.0.2 and below, 6.4.7 and below, and 6.2.9 and below that exposes sensitive information to unauthorized actors.
What is the severity of CVE-2021-43205?
CVE-2021-43205 has a severity score of 5.3 (medium).
How can an unauthenticated attacker exploit CVE-2021-43205?
An unauthenticated attacker can exploit CVE-2021-43205 by accessing the confighandler webserver via external binaries.
Which versions of FortiClient for Linux are affected by CVE-2021-43205?
FortiClient for Linux versions 7.0.2 and below, 6.4.7 and below, and 6.2.9 and below are affected by CVE-2021-43205.
Is there a fix for CVE-2021-43205?
Yes, Fortinet has released patches to address the vulnerability. It is recommended to update to the latest version of FortiClient for Linux.