PT-2021-9846 · Fortinet · Forticlientems
Published
2021-10-06
·
Updated
2021-10-14
·
CVE-2020-15941
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FortiClientEMS versions 6.4.1 and below
FortiClientEMS versions 6.2.8 and below
Description
A path traversal issue in FortiClientEMS may allow an authenticated attacker to inject directory traversal character sequences, enabling them to add or delete server files via the
name parameter of Deployment Packages.Recommendations
For FortiClientEMS versions 6.4.1 and below, update to a version above 6.4.1 to resolve the issue.
For FortiClientEMS versions 6.2.8 and below, update to a version above 6.2.8 to resolve the issue.
As a temporary workaround, consider restricting access to the
name parameter of Deployment Packages to minimize the risk of exploitation.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forticlientems