CVE-2021-42754
published 2021-11-02CVE-2021-42754: An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authenticated…
PriorityP420medium5CVSS 3.1
AVLACLPRLUIRSUCNIHAN
EPSS
0.41%
33.4th percentile
An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authenticated attacker to hijack the MacOS camera without the user permission via the malicious dylib file.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
| fortinet | forticlient | — | — |
| fortinet | forticlient | 6.4.0 – 6.4.5 | — |
| fortinet | forticlientmacos | — | — |
| fortinet | fortinet_forticlientmac | — | — |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5...
vendor_fortinet·2021-11-02·CVSS 3.2
CVE-2021-42754 [LOW] CWE-94 An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5...
FG-IR-21-079: An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5...
An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authenticated attacker to hijack the MacOS camera without the user permission via the malicious dylib file.
CVEs: CVE-2021-42754
CWEs: CWE-94
CVSS: 3.2 (low)
Affected products: FortiClient, FortiClientMacOS
GHSA
GHSA-5vh5-7q79-c2mp: An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7
ghsa_unreviewed·2022-05-24
CVE-2021-42754 [MEDIUM] CWE-94 GHSA-5vh5-7q79-c2mp: An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7
An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authenticated attacker to hijack the MacOS camera without the user permission via the malicious dylib file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-11-02
Published