fortiguard.comConfirmation
https://fortiguard.com/psirt/FG-IR-20-045 CVE-2020-9294
CRITICAL
FortiMail Unauthenticated Login Bypass Scanner
Record summary
CVE-2020-9294 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the user interface.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
FortiMailBrowse Fortinet / FortiMail | CVE List | 5.4.10 | affected |
| 6.0.7 | affected | ||
| 6.2.2 and earlier | affected | ||
FortiVoiceEnterpriseBrowse Fortinet / FortiVoiceEnterprise | CVE List | 6.0.0 | affected |
| 6.0.1 | affected |
Proofs of concept
1Catalogued exploits
MetasploitFortiMail Unauthenticated Login Bypass ScannerMetasploit auxiliary PoCby Juerg Schweingruber <juerg.schweingruber@redguard.ch> +2 moreNot analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-9294