CVE-2021-44172: Infoleak
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 through 7.0.7, in all 6.4 and 6.2 version management interface may allow an unauthenticated attacker to gain information on environment variables such as the EMS installation path.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-44172.
What is the severity rating of CVE-2021-44172?
The severity rating of CVE-2021-44172 is medium, with a severity value of 5.3.
Which software versions are affected by CVE-2021-44172?
FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 through 7.0.7, and all 6.4 and 6.2 version management interfaces are affected by CVE-2021-44172.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-200.
How can an attacker exploit CVE-2021-44172?
An unauthenticated attacker can exploit CVE-2021-44172 to gain information on environment variables such as the EM.