CVE-2020-15933

MEDIUM

FortiMail <=6.0.9/6.2.4/6.4.1 Sensitive Version Info Exposure via Client-Side Inspection

Title source: llm
STIX 2.1

Description

A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail versions 6.2.4 and below FortiMail versions 6.4.1 and 6.4.0 allows attacker to obtain potentially sensitive software-version information via client-side resources inspection.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://fortiguard.com/psirt/FG-IR-20-105

Scores

CVSS v3 5.3
EPSS 0.0024
EPSS Percentile 46.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (8)
fortinet/fortimail 6.2.0
fortinet/fortimail 6.2.1
fortinet/fortimail 6.2.2
fortinet/fortimail 6.2.3
fortinet/fortimail 6.2.4
fortinet/fortimail 6.4.0
fortinet/fortimail 6.4.1
fortinet/fortimail < 6.0.9
Published Jan 05, 2022
Tracked Since Feb 18, 2026