CVE-2020-29018

HIGH

Fortinet Fortiweb < 6.3.5 - Format String Vulnerability

Title source: rule
STIX 2.1

Description

A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the content of memory and retrieve sensitive data via the redir parameter.

Scores

CVSS v3 8.8
EPSS 0.0075
EPSS Percentile 73.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-134
Status published
Products (1)
fortinet/fortiweb 6.3.0 - 6.3.5
Published Jan 14, 2021
Tracked Since Feb 18, 2026