CVE Vulnerabilities

CVE-2020-15942

Insufficiently Protected Credentials

Published: Apr 12, 2021 | Modified: Jun 28, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinets FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may allow a remote authenticated attacker to read the password used by the FortiWeb scanner to access the device defined in the scan profile.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Fortiweb Fortinet 6.2.0 (including) 6.2.3 (including)
Fortiweb Fortinet 6.3.0 (including) 6.3.4 (including)

Potential Mitigations

References