CVE-2021-26089

6.7MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
12 July 2021

Summary

An improper symlink following in FortiClient for Mac 6.4.3 and below may allow an non-privileged user to execute arbitrary privileged shell commands during installation phase.

Affected Version(s)

Fortinet FortiClientMac FortiClientMac 6.4.3 and below

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.