CVE-2023-37939
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/10/2023
Last modified:
07/11/2023
Description
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions, Linux 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions and Mac 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions, 6.2 all versions, may allow a local authenticated attacker with no Administrative privileges to retrieve the list of files or folders excluded from malware scanning.
Impact
Base Score 3.x
3.30
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:* | 6.2.0 (including) | 6.2.9 (including) |
| cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:* | 6.2.0 (including) | 6.2.9 (including) |
| cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:* | 6.2.0 (including) | 6.2.9 (including) |
| cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:* | 6.4.0 (including) | 6.4.9 (including) |
| cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:* | 6.4.0 (including) | 6.4.10 (including) |
| cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:* | 6.4.0 (including) | 6.4.10 (including) |
| cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:* | 7.0.0 (including) | 7.0.9 (including) |
| cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:* | 7.0.0 (including) | 7.0.9 (including) |
| cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:* | 7.0.0 (including) | 7.0.9 (including) |
| cpe:2.3:a:fortinet:forticlient:7.2.0:*:*:*:*:linux:*:* | ||
| cpe:2.3:a:fortinet:forticlient:7.2.0:*:*:*:*:macos:*:* | ||
| cpe:2.3:a:fortinet:forticlient:7.2.0:*:*:*:*:windows:*:* | ||
| cpe:2.3:a:fortinet:forticlient:7.2.1:*:*:*:*:macos:*:* |
To consult the complete list of CPE names with products and versions, see this page



