A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allows attacker to information disclosure via inspecting browser decrypted data
The product does not encrypt sensitive or critical information before storage or transmission.
Link | Tags |
---|---|
https://fortiguard.com/advisory/FG-IR-21-140 | patch vendor advisory |