CVE-2020-15941: Fortinet FortiClient Endpoint Management Server
Medium severity, CVSS 5.4. EPSS: 1.1% chance of exploitation in the next 30 days.
A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authenticated attacker to inject directory traversal character sequences to add/delete the files of the server via the name parameter of Deployment Packages.
Affected products
- Fortinet FortiClient Endpoint Management Server: before 6.2.9 (fixed in 6.2.9); from 6.4.0, before 6.4.2 (fixed in 6.4.2)
Published 2021-10-06. Last modified 2026-06-17.