CVE-2021-44172

Severity
5.3MEDIUM
EPSS
0.5%
top 35.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 13

Description

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 through 7.0.7, in all 6.4 and 6.2 version management interface may allow an unauthenticated attacker to gain information on environment variables such as the EMS installation path.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5fortinet/forticlientems7.0.67.0.7+5

🔴Vulnerability Details

2
GHSA
GHSA-cvf7-h454-x3rj: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 72023-09-13
CVEList
CVE-2021-44172: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 72023-09-13

📋Vendor Advisories

1
Fortinet
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 t...2023-09-13
CVE-2021-44172 (MEDIUM CVSS 5.3) | An exposure of sensitive informatio | cvebase.io