CVE-2019-15704
published 2019-11-21CVE-2019-15704: A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read sensitive information logged in the…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.19%
9.3th percentile
A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read sensitive information logged in the console window when the user connects to an SSL VPN Gateway.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
| fortinet | forticlient | — | — |
| fortinet | forticlient | 6.0.0 – 6.0.7 | — |
| fortinet | forticlient_for_mac_os | — | — |
| fortinet | forticlient_for_mac_os | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read se...
vendor_fortinet·2019-11-21·CVSS 5.5
CVE-2019-15704 [MEDIUM] CWE-311 A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read se...
FG-IR-19-227: A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read se...
A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read sensitive information logged in the console window when the user connects to an SSL VPN Gateway.
CVEs: CVE-2019-15704
CWEs: CWE-311
CVSS: 5.5 (medium)
Affected products: FortiClient
GHSA
GHSA-2w2x-7266-2c97: A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read sensitive information logged in
ghsa_unreviewed·2022-05-24
CVE-2019-15704 [LOW] GHSA-2w2x-7266-2c97: A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read sensitive information logged in
A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read sensitive information logged in the console window when the user connects to an SSL VPN Gateway.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-11-21
Published