CVE-2021-41028

HIGH

FortiClientEMS <7.0.1-6.4.6 - Man-in-the-Middle

Title source: llm
STIX 2.1

Description

A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 and below, 6.4.6 and below may allow an unauthenticated and network adjacent attacker to perform a man-in-the-middle attack between the EMS and the FCT via the telemetry protocol.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-21-075

Scores

CVSS v3 8.2
EPSS 0.0014
EPSS Percentile 34.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295 CWE-798
Status published
Products (7)
fortinet/forticlient 7.0.0 (3 CPE variants)
fortinet/forticlient 7.0.1 (3 CPE variants)
fortinet/forticlient 6.0.0 - 6.0.9 (2 CPE variants)
fortinet/forticlient 6.2.0 - 6.2.9
fortinet/forticlient_endpoint_management_server 7.0.0
fortinet/forticlient_endpoint_management_server 7.0.1
fortinet/forticlient_endpoint_management_server 6.2.0 - 6.2.9
Published Dec 16, 2021
Tracked Since Feb 18, 2026