VYPR
Medium severity4.3NVD Advisory· Published Apr 6, 2022· Updated Jun 17, 2026

CVE-2021-43205

CVE-2021-43205

Description

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and below and 6.2.9 and below may allow an unauthenticated attacker to access the confighandler webserver via external binaries.

Affected products

4
  • cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*+ 3 more
    • cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*range: >=6.2.0,<=6.2.4
    • cpe:2.3:a:fortinet:forticlient:6.4.7:*:*:*:*:linux:*:*
    • (no CPE)range: <=7.0.2, <=6.4.7, <=6.2.9
    • (no CPE)range: FortiClientLinux 7.0.2 and below, 6.4.7 and below, 6.2.9 and below

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.