CVE-2021-32592

CWE-4274 documents4 sources
Severity
7.8HIGH
EPSS
0.1%
top 83.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 1
Latest updateDec 2

Description

An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x may allow an attacker to perform a DLL Hijack attack on affected devices via a malicious OpenSSL engine library in the search path.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/forticlient6.4.06.4.7+3

🔴Vulnerability Details

2
GHSA
GHSA-2cg5-v97f-xqfq: An unsafe search path vulnerability in FortiClientWindows 72021-12-02
CVEList
CVE-2021-32592: An unsafe search path vulnerability in FortiClientWindows 72021-12-01

📋Vendor Advisories

1
Fortinet
An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0,...2021-12-01
CVE-2021-32592 (HIGH CVSS 7.8) | An unsafe search path vulnerability | cvebase.io