PT-2021-21153 · Fortinet · Forticlient
Published
2021-12-09
·
Updated
2022-07-12
·
CVE-2021-36167
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FortiClient Windows versions 6.2.8 and below
FortiClient Windows versions 6.4.6 and below
FortiClient Windows version 7.0.0
Description
An improper authorization issue may allow an unauthenticated attacker to bypass the webfilter control via modifying the
session-id parameter. This could potentially lead to unauthorized access.Recommendations
For FortiClient Windows versions 6.2.8 and below, update to a version above 6.2.8 to resolve the issue.
For FortiClient Windows versions 6.4.6 and below, update to a version above 6.4.6 to resolve the issue.
For FortiClient Windows version 7.0.0, update to a version above 7.0.0 to resolve the issue.
As a temporary workaround, consider restricting access to the webfilter control to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Forticlient