CVE Vulnerabilities

CVE-2020-9294

Improper Authentication

Published: Apr 27, 2020 | Modified: Jan 18, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the user interface.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Fortimail Fortinet * 5.4.10 (including)
Fortimail Fortinet 6.0.0 (including) 6.0.7 (including)
Fortimail Fortinet 6.2.0 (including) 6.2.2 (including)
Fortivoice Fortinet 6.0.0 (including) 6.0.1 (including)

Potential Mitigations

References