Description
An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiClientMac version 7.2.4 or above Please upgrade to FortiClientMac version 7.0.11 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-29372 | An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-345 |
|
History
Thu, 23 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet forticlient |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:* | |
| Vendors & Products |
Fortinet
Fortinet forticlient |
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-08-22T18:27:36.614Z
Reserved: 2024-04-04T12:52:41.586Z
Link: CVE-2024-31492
Updated: 2024-08-02T01:52:57.265Z
Status : Analyzed
Published: 2024-04-10T13:51:38.607
Modified: 2025-01-23T15:58:57.733
Link: CVE-2024-31492
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD