CVE-2019-15704

CWE-3114 documents4 sources
Severity
5.5MEDIUM
EPSS
0.0%
top 93.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 21
Latest updateMay 24

Description

A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read sensitive information logged in the console window when the user connects to an SSL VPN Gateway.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDfortinet/forticlient6.0.06.0.7+1
CVEListV5fortinet/forticlient_for_mac_os6.0.7, FortiClient for Mac OS 6.2.0+1

🔴Vulnerability Details

2
GHSA
GHSA-2w2x-7266-2c97: A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read sensitive information logged in2022-05-24
CVEList
CVE-2019-15704: A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read sensitive information logged in2019-11-21

📋Vendor Advisories

1
Fortinet
A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read se...2019-11-21