CVE-2022-33878: Infoleak
Published Nov 2, 2022
·Updated
An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiClient for Mac versions 7.0.0 through 7.0.5 may allow a local authenticated attacker to obtain the SSL-VPN password in cleartext via running a logstream for the FortiTray process in the terminal.
Affected Software
1 affected component
Fortinet Forticlient Macos>=7.0.0<=7.0.5
Remediation
Patch Available
Event History
Nov 2, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-33878.
2
What is the severity of CVE-2022-33878?
The severity of CVE-2022-33878 is medium, with a severity value of 5.5.
3
What software versions are affected by CVE-2022-33878?
FortiClient for Mac versions 7.0.0 through 7.0.5 are affected by CVE-2022-33878.
4
What is the CWE ID associated with CVE-2022-33878?
The CWE ID associated with CVE-2022-33878 is CWE-200.
5
How can an attacker exploit CVE-2022-33878?
A local authenticated attacker can obtain the SSL-VPN password in cleartext by running a logstream for the FortiTray process in the terminal.