Security Advisory

CVE-2021-36167

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-12-09 09:33:17
Last updated 2024-10-25 13:37:00
Assigner fortinet
State PUBLISHED

Description

An improper authorization vulnerabiltiy [CWE-285] in FortiClient Windows versions 7.0.0 and 6.4.6 and below and 6.2.8 and below may allow an unauthenticated attacker to bypass the webfilter control via modifying the session-id paramater.