Medium severity4.3NVD Advisory· Published Apr 6, 2022· Updated Jun 17, 2026
CVE-2021-43205
CVE-2021-43205
Description
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and below and 6.2.9 and below may allow an unauthenticated attacker to access the confighandler webserver via external binaries.
Affected products
4cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*+ 3 more
- cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*range: >=6.2.0,<=6.2.4
- cpe:2.3:a:fortinet:forticlient:6.4.7:*:*:*:*:linux:*:*
- (no CPE)range: <=7.0.2, <=6.4.7, <=6.2.9
- (no CPE)range: FortiClientLinux 7.0.2 and below, 6.4.7 and below, 6.2.9 and below
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-21-226nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.