CVE-2020-15934

HIGH

FortiClient for Linux 6.2.7 and below, 6.4.0 - Privilege Escalation via VCM Engine

Title source: llm
STIX 2.1

Description

An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to elevate their privileges to root by creating a malicious script or program on the target machine.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0009
EPSS Percentile 25.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (2)
fortinet/forticlient 6.4.0
fortinet/forticlient 6.0.0 - 6.2.8
Published Dec 19, 2024
Tracked Since Feb 18, 2026