CVE-2020-15942 MEDIUM

CVE-2020-15942

Vendor Fortinet
Product Fortinet FortiWeb
Published April 12, 2021
Last update October 25, 2024

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may allow a remote authenticated attacker to read the password used by the FortiWeb scanner to access the device defined in the scan profile.

Key dates

02Disclosure timeline

April 12, 2021 CVE published
October 25, 2024 Record updated