ZDI-CAN-18590: ZDI-23-1104: Fortinet FortiClient VPN Improper Access Control Remote Code Execution Vulnerability
Published Aug 14, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiClient VPN. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
Fortinet FortiClient VPN
Event History
Aug 14, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-18590?
The severity of ZDI-CAN-18590 is critical, as it allows remote code execution by authenticated attackers.
2
How do I fix ZDI-CAN-18590?
To fix ZDI-CAN-18590, update Fortinet FortiClient VPN to the latest version provided by the vendor.
3
What versions of Fortinet FortiClient VPN are affected by ZDI-CAN-18590?
ZDI-CAN-18590 affects various versions of Fortinet FortiClient VPN that have not been patched.
4
Is authentication required to exploit ZDI-CAN-18590?
Yes, ZDI-CAN-18590 requires authentication to exploit the vulnerability.
5
What type of attacks can ZDI-CAN-18590 enable?
ZDI-CAN-18590 can enable remote attackers to execute arbitrary code on affected Fortinet FortiClient VPN installations.