CVE-2021-44172

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 through 7.0.7, in all 6.4 and 6.2 version management interface may allow an unauthenticated attacker to gain information on environment variables such as the EMS installation path.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-21-244 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:forticlient_endpoint_management_server:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlient_endpoint_management_server:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlient_endpoint_management_server:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlient_endpoint_management_server:*:*:*:*:*:*:*:*

History

15 Sep 2023, 15:25

Type Values Removed Values Added
First Time Fortinet
Fortinet forticlient Endpoint Management Server
References (MISC) https://fortiguard.com/psirt/FG-IR-21-244 - (MISC) https://fortiguard.com/psirt/FG-IR-21-244 - Vendor Advisory
CPE cpe:2.3:a:fortinet:forticlient_endpoint_management_server:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-200

13 Sep 2023, 13:57

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-13 13:15

Updated : 2023-12-10 15:14


NVD link : CVE-2021-44172

Mitre link : CVE-2021-44172

CVE.ORG link : CVE-2021-44172


JSON object : View

Products Affected

fortinet

  • forticlient_endpoint_management_server
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor