Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Please upgrade to FortiClientMac version 7.2.4 or above Please upgrade to FortiClientMac version 7.0.11 or above
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-49880 | An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process. |
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-345 |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet forticlient |
|
| CPEs | cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:* | |
| Vendors & Products |
Fortinet
Fortinet forticlient |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 14 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Mar 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process. | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-03-14T17:40:22.223Z
Reserved: 2023-10-09T08:01:29.297Z
Link: CVE-2023-45588
Updated: 2025-03-14T17:40:16.636Z
Status : Analyzed
Published: 2025-03-14T16:15:27.570
Modified: 2025-07-15T17:03:46.857
Link: CVE-2023-45588
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:23:51Z
EUVD