PT-2021-21153 · Fortinet · Forticlient

Published

2021-12-09

·

Updated

2022-07-12

·

CVE-2021-36167

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions FortiClient Windows versions 6.2.8 and below FortiClient Windows versions 6.4.6 and below FortiClient Windows version 7.0.0
Description An improper authorization issue may allow an unauthenticated attacker to bypass the webfilter control via modifying the session-id parameter. This could potentially lead to unauthorized access.
Recommendations For FortiClient Windows versions 6.2.8 and below, update to a version above 6.2.8 to resolve the issue. For FortiClient Windows versions 6.4.6 and below, update to a version above 6.4.6 to resolve the issue. For FortiClient Windows version 7.0.0, update to a version above 7.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the webfilter control to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-36167

Affected Products

Forticlient