CVE-2020-15934
published 2024-12-19CVE-2020-15934: An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.5th percentile
An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to elevate their privileges to root by creating a malicious script or program on the target machine.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
| fortinet | forticlient | — | — |
| fortinet | forticlient | >= 6.0.0 < 6.2.8 | 6.2.8 |
| fortinet | forticlientlinux | — | — |
| fortinet | forticlientlinux | — | — |
| fortinet | forticlientlinux | 6.0.0 – 6.0.6 | — |
| fortinet | forticlientlinux | 6.2.0 – 6.2.4 | — |
| fortinet | forticlientlinux | 6.2.6 – 6.2.7 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and bel...
vendor_fortinet·2024-12-19·CVSS 8.8
CVE-2020-15934 [HIGH] CWE-269 An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and bel...
FG-IR-20-110: An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and bel...
An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to elevate their privileges to root by creating a malicious script or program on the target machine.
CVEs: CVE-2020-15934
CWEs: CWE-269
CVSS: 8.8 (high)
Affected products: FortiClient
GHSA
GHSA-8prr-359h-f8c7: An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6
ghsa_unreviewed·2024-12-19
CVE-2020-15934 [HIGH] CWE-269 GHSA-8prr-359h-f8c7: An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6
An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to elevate their privileges to root by creating a malicious script or program on the target machine.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-12-19
Published