PT-2009-3799 · Fortinet · Forticlient

Published

2009-04-07

·

Updated

2018-10-10

·

CVE-2009-1262

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiClient versions 3.0.614 and earlier
Description A format string issue allows local users to execute arbitrary code via format string specifiers in the VPN connection name.
Recommendations For FortiClient versions 3.0.614 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1262

Affected Products

Forticlient