PT-2024-2719 · Fortinet · Forticlientlinux
Published
2024-04-09
·
Updated
2025-01-17
·
CVE-2023-45590
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiClientLinux versions 7.0.3 through 7.0.4
FortiClientLinux versions 7.0.6 through 7.0.10
FortiClientLinux version 7.2.0
Description
An improper control of generation of code ('code injection') in FortiClientLinux allows an attacker to execute unauthorized code or commands via tricking a FortiClientLinux user into visiting a malicious website. The exploitation of this issue may allow a remote attacker to execute arbitrary code if the user visits a specially crafted malicious website.
Recommendations
For FortiClientLinux versions 7.0.3 through 7.0.4, upgrade to version 7.0.11 or higher to mitigate the risk.
For FortiClientLinux versions 7.0.6 through 7.0.10, upgrade to version 7.0.11 or higher to mitigate the risk.
For FortiClientLinux version 7.2.0, upgrade to version 7.2.1 or higher to mitigate the risk.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forticlientlinux