Fortinet Rolls Out Critical Security Patches for FortiClientLinux Vulnerability
ID: 031766de-7d2d-5ebc-943e-47663970761c
STIX ID: report--031766de-7d2d-5ebc-943e-47663970761c
Feed Name: The Hacker News
Fortinet released patches for a critical FortiClientLinux vulnerability (CVE-2023-45590, CVSS 9.4) that can enable unauthenticated arbitrary code execution via a code-injection issue tied to an unsafe Node.js configuration; affected versions include FortiClientLinux 7.0.3–7.0.4, 7.0.6–7.0.10 (upgrade to 7.0.11+) and 7.2.0 (upgrade to 7.2.1+). The advisory also notes related FortiClientMac and FortiOS/FortiProxy fixes, credits the researcher, and states there is no evidence of exploitation in the wild while urging users to update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
