An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-345 |
|
History
Thu, 23 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet forticlient |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:* | |
| Vendors & Products |
Fortinet
Fortinet forticlient |
Status: PUBLISHED
Assigner: fortinet
Published: 2024-04-10T13:24:56.859Z
Updated: 2024-08-22T18:27:36.614Z
Reserved: 2024-04-04T12:52:41.586Z
Link: CVE-2024-31492
Updated: 2024-08-02T01:52:57.265Z
Status : Analyzed
Published: 2024-04-10T13:51:38.607
Modified: 2025-01-23T15:58:57.733
Link: CVE-2024-31492
No data.