ZDI-23-1104: Fortinet FortiClient VPN Improper Access Control Remote Code Execution Vulnerability
Published Aug 14, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiClient VPN. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
Fortinet FortiClient VPN
Event History
Aug 14, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1104?
The severity of ZDI-23-1104 is considered high due to its potential to allow remote code execution.
2
How do I fix ZDI-23-1104?
To fix ZDI-23-1104, ensure that you update your Fortinet FortiClient VPN to the latest version provided by the vendor.
3
What types of attacks can ZDI-23-1104 enable?
ZDI-23-1104 can enable remote attackers to execute arbitrary code on vulnerable installations.
4
Is authentication required to exploit ZDI-23-1104?
Yes, authentication is required to exploit the vulnerability ZDI-23-1104.
5
What software is affected by ZDI-23-1104?
The software affected by ZDI-23-1104 is Fortinet FortiClient VPN.