CVE-2023-45590

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
09/04/2024
Last modified:
17/01/2025

Description

An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4 allows attacker to execute unauthorized code or commands via tricking a FortiClientLinux user into visiting a malicious website

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:* 7.0.6 (including) 7.0.11 (excluding)
cpe:2.3:a:fortinet:forticlient:7.0.3:*:*:*:*:linux:*:*
cpe:2.3:a:fortinet:forticlient:7.0.4:*:*:*:*:linux:*:*
cpe:2.3:a:fortinet:forticlient:7.2.0:*:*:*:*:linux:*:*