CVE-2020-15934

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
19/12/2024
Last modified:
21/01/2025

Description

An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to elevate their privileges to root by creating a malicious script or program on the target machine.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:* 6.0.0 (including) 6.2.8 (excluding)
cpe:2.3:a:fortinet:forticlient:6.4.0:*:*:*:*:linux:*:*


References to Advisories, Solutions, and Tools