ZeroHour

CVE-2017-14184

CVSS 3.0
8.8 high
EPSS
2%p80
Published
()
Modified
Description

An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions allows regular users to see each other's VPN authentication credentials due to improperly secured storage locations.

Vendors
fortinet
Products
forticlient, forticlient sslvpn client
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news