PT-2021-9846 · Fortinet · Forticlientems

Published

2021-10-06

·

Updated

2021-10-14

·

CVE-2020-15941

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions FortiClientEMS versions 6.4.1 and below FortiClientEMS versions 6.2.8 and below
Description A path traversal issue in FortiClientEMS may allow an authenticated attacker to inject directory traversal character sequences, enabling them to add or delete server files via the name parameter of Deployment Packages.
Recommendations For FortiClientEMS versions 6.4.1 and below, update to a version above 6.4.1 to resolve the issue. For FortiClientEMS versions 6.2.8 and below, update to a version above 6.2.8 to resolve the issue. As a temporary workaround, consider restricting access to the name parameter of Deployment Packages to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15941

Affected Products

Forticlientems