VYPR

Forticlient

by Fortinet

CVEs (91)

  • CVE-2022-40682HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.00

    A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe.

  • CVE-2021-41031HigJul 18, 2022
    risk 0.51cvss 7.8epss 0.00

    A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior and 6.2.9 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for FortiESNAC service.

  • CVE-2021-32592HigDec 1, 2021
    risk 0.51cvss 7.8epss 0.00

    An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x may allow an attacker to perform a DLL Hijack attack on affected devices via a malicious OpenSSL engine library in the search…

  • CVE-2020-9290HigMar 15, 2020
    risk 0.51cvss 7.8epss 0.01

    An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineInstaller.exe resides to execute arbitrary code on the…

  • CVE-2020-9287HigMar 15, 2020
    risk 0.51cvss 7.8epss 0.01

    An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in which FortiClientEMSOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library…

  • CVE-2019-15711HigFeb 6, 2020
    risk 0.51cvss 7.8epss 0.01

    A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to run system commands under root privilege via injecting specially crafted "ExportLogs" type IPC client requests to the fctsched process.

  • CVE-2019-17650HigNov 21, 2019
    risk 0.51cvss 7.8epss 0.00

    An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root processes, may allow a local user of the system on which FortiClient is running to execute unauthorized code as root by bypassing a security check.

  • CVE-2019-6692HigOct 24, 2019
    risk 0.51cvss 7.8epss 0.01

    A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker to perform arbitrary code execution via forging that DLL.

  • CVE-2018-9193HigMay 30, 2019
    risk 0.51cvss 7.8epss 0.00

    A researcher has disclosed several vulnerabilities against FortiClient for Windows version 6.0.5 and below, version 5.6.6, the combination of these vulnerabilities can turn into an exploit chain, which allows a user to gain system privileges on Microsoft Windows.

  • CVE-2018-9191HigMay 30, 2019
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attackers to execute unauthorized code or commands via the named pipe responsible for Forticlient updates.

  • CVE-2018-13368HigMay 30, 2019
    risk 0.51cvss 7.8epss 0.01

    A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attacker to execute unauthorized code or commands via the command injection.

  • CVE-2019-5589HigMay 28, 2019
    risk 0.51cvss 7.8epss 0.03

    An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthenticated, remote attacker with control over the directory in which FortiClientOnlineInstaller.exe resides to execute arbitrary code on the system via uploading…

  • CVE-2015-7362HigJan 8, 2016
    risk 0.51cvss 7.8epss 0.00

    Fortinet FortiClient Linux SSLVPN before build 2313, when installed on Linux in a home directory that is world readable and executable, allows local users to gain privileges via the helper/subroc setuid program.

  • CVE-2024-3661HigMay 6, 2024
    risk 0.50cvss 7.6epss 0.04

    DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt,…

  • CVE-2022-26113HigJul 19, 2022
    risk 0.50cvss 7.7epss 0.00

    An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.10 may allow a local attacker to perform an arbitrary file write on the system.

  • CVE-2025-46774HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.00

    An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClient related executables.

  • CVE-2024-40592HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.00

    An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package…

  • CVE-2022-43946HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on the same file…

  • CVE-2017-17543HigApr 26, 2018
    risk 0.49cvss 7.5epss 0.00

    Users' VPN authentication credentials are unsafely encrypted in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2335 and below versions, due to the use of a static encryption…

  • CVE-2021-36183HigNov 2, 2021
    risk 0.48cvss 7.4epss 0.00

    An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.

Page 2 of 5