Known vulnerabilities in Fortinet FortiClient for Windows - page 2

Software CPE: cpe:2.3:a:fortinet:fortinet_forticlient:*:*:*:*:*:*:*:*
Total vulnerabilities: 49
Public exploits: 1
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Fortinet FortiClient for Windows Fortinet FortiClient for Windows is affected by 49 known vulnerabilities: 1 critical, 4 high, 12 medium, 32 low Critical High Medium Low

Vulnerabilities (49)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU83268 - Incorrect Authorization
CVE-2022-40681
CWE-863 Low
No
No
6.4.9, 7.0.8, 7.2.0 20.11.2023 SB2023112009
#VU83266 - Use of Hard-coded Credentials
CVE-2023-33304
CWE-798 Low
No
No
7.0.10, 7.2.2 20.11.2023 SB2023112008
#VU83265 - Untrusted Search Path
CVE-2023-41840
CWE-426 Low
No
No
7.0.10, 7.2.2 20.11.2023 SB2023112008
#VU81942 - Exposure of sensitive information to an unauthorized actor
CVE-2023-37939
CWE-200 Low
No
No
7.2.1 12.10.2023 SB2023101237
#VU77194 - Incorrect Default Permissions
CVE-2022-33877
CWE-276 Low
No
No
6.4.9, 7.0.7 13.06.2023 SB2023061324
#VU74985 - Incorrect Authorization
CVE-2022-40682
CWE-863 Low
No
No
7.0.8 11.04.2023 SB20230411102
#VU74983 - Incorrect Permission Assignment for Critical Resource
CVE-2022-43946
CWE-732 Medium
No
No
7.0.8 11.04.2023 SB20230411102
#VU74982 - External Control of File Name or Path
CVE-2022-42470
CWE-73 Low
No
No
7.0.8 11.04.2023 SB20230411102
#VU64936 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-41031
CWE-22 Low
No
No
6.4.7, 7.0.3 05.07.2022 SB2022070530
#VU64050 - Execution with Unnecessary Privileges
CVE-2022-26113
CWE-250 Low
No
No
6.4.8, 7.0.4 07.06.2022 SB2022060727
#VU62774 - External Control of File Name or Path
CVE-2021-43066
CWE-73 Low
No
No
6.4.7, 7.0.3 03.05.2022 SB2022050320
#VU61981 - Improper Initialization
CVE-2021-44169
CWE-665 Low
No
No
6.4.8, 7.0.3 07.04.2022 SB2022040713
#VU58431 - Uncontrolled Search Path Element
CVE-2021-32592
CWE-427 Low
No
No
6.4.7, 7.0.1 29.11.2021 SB2021112912
#VU56394 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2021-22127
CWE-78 Medium
No
No
6.2.9, 6.4.3 08.09.2021 SB2021090807
#VU54205 - UNIX Symbolic Link (Symlink) Following
CVE-2021-26089
CWE-61 Low
No
No
6.4.4, 7.0.0 17.06.2021 SB2021061717
#VU48748 - Protection Mechanism Failure
CVE-2020-9295
CWE-693 Medium
No
No
- 02.12.2020 SB2020120210
#VU47108 - Improper Validation of Certificate with Host Mismatch
CWE-297 High
No
No
- 25.09.2020 SB2020092501
#VU28499 - Use of Hard-coded Cryptographic Key
CWE-321 Medium
No
No
6.4.0 02.06.2020 SB2020060203
#VU28258 - Insecure Temporary File
CVE-2020-9291
CWE-377 Low
No
No
6.2.2 26.05.2020 SB2020052615
#VU47346 - Uncontrolled Search Path Element
CVE-2020-9290
CWE-427 Low
No
No
6.2.4 15.03.2020 SB2020031538


Showing elements 21 - 40 out of 49