CVE-2020-15934

An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to elevate their privileges to root by creating a malicious script or program on the target machine.
References
Link Resource
https://www.fortiguard.com/psirt/FG-IR-20-110 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*
cpe:2.3:a:fortinet:forticlient:6.4.0:*:*:*:*:linux:*:*

History

21 Jan 2025, 20:38

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de ejecución con privilegios innecesarios en el motor VCM de FortiClient para Linux versiones 6.2.7 y anteriores, versión 6.4.0, puede permitir que usuarios locales eleven sus privilegios a superusuario mediante la creación de un script o programa malicioso en la máquina de destino.
References () https://www.fortiguard.com/psirt/FG-IR-20-110 - () https://www.fortiguard.com/psirt/FG-IR-20-110 - Vendor Advisory
First Time Fortinet
Fortinet forticlient
CPE cpe:2.3:a:fortinet:forticlient:6.4.0:*:*:*:*:linux:*:*
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:linux:*:*

19 Dec 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-19 11:15

Updated : 2025-01-21 20:38


NVD link : CVE-2020-15934

Mitre link : CVE-2020-15934

CVE.ORG link : CVE-2020-15934


JSON object : View

Products Affected

fortinet

  • forticlient
CWE
CWE-269

Improper Privilege Management