5.4
CVSSv2

CVE-2021-41028

Published: 16/12/2021 Updated: 04/01/2022
CVSS v2 Base Score: 5.4 | Impact Score: 6.4 | Exploitability Score: 5.5
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 481
Vector: AV:A/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 and below, 6.4.6 and below may allow an unauthenticated and network adjacent malicious user to perform a man-in-the-middle attack between the EMS and the FCT via the telemetry protocol.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fortinet forticlient

fortinet forticlient 7.0.0

fortinet forticlient 7.0.1

fortinet forticlient endpoint management server

fortinet forticlient endpoint management server 7.0.0

fortinet forticlient endpoint management server 7.0.1