PT-2022-9229 · Fortinet · Forticlient

Published

2022-04-06

·

Updated

2022-04-13

·

CVE-2021-22127

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiClient for Linux versions 6.2.x through 6.2.8 FortiClient for Linux versions 6.4.x through 6.4.2
Description An improper input validation issue may allow an unauthenticated attacker to execute arbitrary code on the host operating system as root via tricking the user into connecting to a network with a malicious name.
Recommendations For FortiClient for Linux versions 6.2.x through 6.2.8, update to version 6.2.9 or later. For FortiClient for Linux versions 6.4.x through 6.4.2, update to version 6.4.3 or later.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22127

Affected Products

Forticlient