CVE-2022-33877: High severity fortinet forticlient ssl vpn vulnerability
An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated attacker to tamper with files in the installation folder, if FortiClient or FortiConverter is installed in an insecure folder.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2022-33877.
What is the severity of CVE-2022-33877?
CVE-2022-33877 has a severity score of 5.5, which is considered high.
Which software versions are affected by CVE-2022-33877?
FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8, as well as FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0, and all versions of 6.0.0 are affected.
What is the CWE classification of CVE-2022-33877?
CVE-2022-33877 is classified as CWE-276.
How can I fix the vulnerability CVE-2022-33877?
To fix CVE-2022-33877, it is recommended to update FortiClient (Windows) to versions 7.0.7 or later, or 6.4.9 or later, and FortiConverter (Windows) to versions 6.2.2 or later, or 7.0.1 or later.