PT-2021-7468 · Fortinet · Fortiweb

Published

2021-04-06

·

Updated

2021-04-20

·

CVE-2020-15942

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FortiWeb versions 6.2.x through 6.2.3 FortiWeb versions 6.3.x through 6.3.4
Description An information disclosure issue in the Web Vulnerability Scan profile of Fortinet's FortiWeb may allow a remote authenticated attacker to read the password used by the FortiWeb scanner to access the device defined in the scan profile. This is related to insufficient protection of credentials.
Recommendations For FortiWeb versions 6.2.x through 6.2.3, update to version 6.2.4 or later. For FortiWeb versions 6.3.x through 6.3.4, update to version 6.3.5 or later.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06592
CVE-2020-15942

Affected Products

Fortiweb