Описание
An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrary code on the victim's host via tricking the user into visiting a malicious website.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 7.2.1 (включая) до 7.2.9 (исключая)Версия от 7.4.0 (включая) до 7.4.4 (исключая)
Одно из
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:*
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:*
EPSS
Процентиль: 11%
0.00037
Низкий
5.8 Medium
CVSS3
7.1 High
CVSS3
Дефекты
CWE-94
Связанные уязвимости
CVSS3: 5.8
github
4 месяца назад
An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrary code on the victim's host via tricking the user into visiting a malicious website.
EPSS
Процентиль: 11%
0.00037
Низкий
5.8 Medium
CVSS3
7.1 High
CVSS3
Дефекты
CWE-94