imPC@ndo IT

Tracker / CVE-2021-32592

CVE-2021-32592

High 7.8

An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x may allow an attacker to perform a DLL Hijack attack on affected devices via a malicious OpenSSL engine library in the search path.

Affected products and versions

fortinet forticlient
fortinet forticlient · 6.0.0 → 6.0.9
fortinet forticlient · 6.2.0 → 6.2.9
fortinet forticlient · 6.4.0 → 6.4.7
fortinet forticlient_enterprise_management_server
fortinet forticlient_enterprise_management_server · 6.0.0 → 6.0.6
fortinet forticlient_enterprise_management_server · 6.2.0 → 6.2.9
fortinet forticlient_enterprise_management_server · 6.4.0 → 6.4.7

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References