CVE-2020-15941
06.10.2021, 10:15
A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authenticated attacker to inject directory traversal character sequences to add/delete the files of the server via the name parameter of Deployment Packages.
| Vendor | Product | Version |
|---|---|---|
| fortinet | forticlient_endpoint_management_server | 𝑥 < 6.2.9 |
| fortinet | forticlient_endpoint_management_server | 6.4.0 ≤ 𝑥 < 6.4.2 |
𝑥
= Vulnerable software versions