CVE-2019-17652

Description

A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to cause FortiClient processes running under root priviledge crashes via sending specially crafted StartAvCustomScan type IPC client requests to the fctsched process due the argv data not been well sanitized.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.425

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Forticlient 6.2.1Windows
Out-of-bounds Write Vulnerability (CVE-2019-17652)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234