Man-in-the-middle Attack Vulnerability in Fortinet FortiClient Products
CVE-2021-41028
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 16 December 2021
What is CVE-2021-41028?
The vulnerability arises from the use of hard-coded cryptographic keys in versions of FortiClientEMS and improper certificate validation in FortiClient for Windows, Linux, and Mac. This flawed implementation enables an unauthenticated and network-adjacent attacker to potentially execute a man-in-the-middle attack through the telemetry protocol, compromising secure communication between the EMS and FortiClient.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Fortinet FortiClientEMS, FortiClientWindows, FortiClientLinux, FortiClientMac FortiClientEMS 7.0.1 and below, 6.4.6 and below, FortiClientWindows, FortiClientLinux, FortiClientMac 7.0.1 and below, 6.4.6 and below.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved