Vulnerability Description
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the user interface.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortimail | <= 5.4.10 |
| Fortinet | Fortivoice | >= 6.0.0, <= 6.0.1 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/psirt/FG-IR-20-045Vendor Advisory
- https://fortiguard.com/psirt/FG-IR-20-045Vendor Advisory
FAQ
What is CVE-2020-9294?
CVE-2020-9294 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a le...
How severe is CVE-2020-9294?
CVE-2020-9294 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-9294?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortimail, Fortinet Fortivoice.