We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2022-33878



Description

An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiClient for Mac versions 7.0.0 through 7.0.5 may allow a local authenticated attacker to obtain the SSL-VPN password in cleartext via running a logstream for the FortiTray process in the terminal.

Reserved 2022-06-16 | Published 2022-11-02 | Updated 2024-10-22 | Assigner fortinet


LOW: 2.2CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N/E:F/RL:U/RC:C

Problem types

Information disclosure

Product status

FortiClientMac 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0
affected

References

fortiguard.com/psirt/FG-IR-22-246

cve.org (CVE-2022-33878)

nvd.nist.gov (CVE-2022-33878)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2022-33878

Support options

Helpdesk Chat, Email, Knowledgebase