CVE-2020-15936

LOW

FortiOS < 5.6.13 - Sensitive Information Disclosure via SNI Client Hello TLS Packets

Title source: llm
STIX 2.1

Description

A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and below, version 5.6.13 and below allows attacker to disclose sensitive information via SNI Client Hello TLS packets.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-20-091

Scores

CVSS v3 2.6
EPSS 0.0034
EPSS Percentile 56.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
fortinet/fortios 5.6.0 - 5.6.13
Published Mar 01, 2022
Tracked Since Feb 18, 2026