High severity7.0NVD Advisory· Published Jun 13, 2023· Updated Jun 17, 2026
CVE-2022-33877
CVE-2022-33877
Description
An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated attacker to tamper with files in the installation folder, if FortiClient or FortiConverter is installed in an insecure folder.
Affected products
9cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*+ 2 more
- cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*range: >=6.4.0,<=6.4.8
- (no CPE)range: 7.0.0-7.0.6, 6.4.0-6.4.8
- (no CPE)range: 7.0.0
cpe:2.3:a:fortinet:forticonverter:*:*:*:*:*:windows:*:*+ 5 more
- cpe:2.3:a:fortinet:forticonverter:*:*:*:*:*:windows:*:*range: >=6.0.0,<=6.0.3
- cpe:2.3:a:fortinet:forticonverter:6.2.0:*:*:*:*:windows:*:*
- cpe:2.3:a:fortinet:forticonverter:6.2.1:*:*:*:*:windows:*:*
- cpe:2.3:a:fortinet:forticonverter:7.0.0:*:*:*:*:windows:*:*
- (no CPE)range: 6.2.0-6.2.1, 7.0.0, 6.0.0
- (no CPE)range: 7.0.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-22-229nvdVendor Advisory
News mentions
0No linked articles in our index yet.