Vulnerability Description
A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and RADIUS shared secret by deobfuscating the passwords entry fields.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortiadc | >= 5.0.0, <= 5.4.3 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/advisory/FG-IR-20-044Vendor Advisory
- https://fortiguard.com/advisory/FG-IR-20-044Vendor Advisory
FAQ
What is CVE-2020-15935?
CVE-2020-15935 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users...
How severe is CVE-2020-15935?
CVE-2020-15935 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15935?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortiadc.