CVE-2021-44167: High severity fortinet forticlient vulnerability
Published May 11, 2022
·Updated
An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6.4.7 and below, 7.0.2 and below may allow an unauthenticated attacker to access sensitive information in log files and directories via symbolic links.
Affected Software
4 affected components
Fortinet FortiClient Linux>=6.0.0<=6.0.8
Fortinet FortiClient Linux>=6.2.0<=6.2.9
Fortinet FortiClient Linux>=6.4.0<=6.4.7
Fortinet FortiClient Linux>=7.0.0<=7.0.2
Event History
May 11, 2022
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-44167.
2
What is the severity of CVE-2021-44167?
CVE-2021-44167 has a severity level of 7.5 (high).
3
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-732.
4
Which versions of FortiClient for Linux are affected by CVE-2021-44167?
FortiClient for Linux versions 6.0.8 and below, 6.2.9 and below, 6.4.7 and below, and 7.0.2 and below are affected by CVE-2021-44167.
5
How can an unauthenticated attacker exploit CVE-2021-44167?
An unauthenticated attacker can exploit CVE-2021-44167 by accessing sensitive information in log files and directories via symbolic links.