Vulnerability Description
An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root processes, may allow a local user of the system on which FortiClient is running to execute unauthorized code as root by bypassing a security check.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Forticlient | <= 6.2.1 |
Related Weaknesses (CWE)
References
- https://danishcyberdefence.dk/blog/forticlient_mac
- https://fortiguard.com/advisory/FG-IR-19-210Vendor Advisory
- https://danishcyberdefence.dk/blog/forticlient_mac
- https://fortiguard.com/advisory/FG-IR-19-210Vendor Advisory
FAQ
What is CVE-2019-17650?
CVE-2019-17650 is a vulnerability with a CVSS score of 7.8 (HIGH). An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root processes, may allow a local user of the system on which FortiClient is running to ...
How severe is CVE-2019-17650?
CVE-2019-17650 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-17650?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Forticlient.