CVE-2024-35281 - CERT CVE
ID CVE-2024-35281
Sažetak An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables.
Reference
CVSS
Base: 2.5
Impact: 1.4
Exploitability:1.0
Pristup
VektorSloženostAutentikacija
LOCAL HIGH LOW
Impact
PovjerljivostCjelovitostDostupnost
NONE LOW NONE
CVSS vektor CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Zadnje važnije ažuriranje 13-05-2025 - 19:35
Objavljeno 13-05-2025 - 15:15