Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fgjm-rj9j-x5wp

Опубликовано: 13 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated attacker to tamper with files in the installation folder, if FortiClient or FortiConverter is installed in an insecure folder.

An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated attacker to tamper with files in the installation folder, if FortiClient or FortiConverter is installed in an insecure folder.

EPSS

Процентиль: 9%
0.00034
Низкий

7 High

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 7
nvd
больше 2 лет назад

An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated attacker to tamper with files in the installation folder, if FortiClient or FortiConverter is installed in an insecure folder.

CVSS3: 7
fstec
больше 2 лет назад

Уязвимость конфигурация дистрибутивов установщика средства защиты FortiClient и службы миграции брандмауэра FortiConverter, позволяющая нарушителю заменить файлы в каталоге установки программного обеспечения

EPSS

Процентиль: 9%
0.00034
Низкий

7 High

CVSS3

Дефекты

CWE-276