CVE-2020-12820
published 2024-12-19CVE-2020-12820: Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker…
PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.86%
54.3th percentile
Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary code via requesting a large FortiClient file name. We are not aware of proof of concept code successfully achieving the latter.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
| fortinet | fortios | < 5.6.13 | 5.6.13 |
| fortinet | fortios | — | — |
| fortinet | fortios | 5.6.0 – 5.6.12 | — |
| fortinet | fortios | >= 6.0.0 < 6.0.11 | 6.0.11 |
| fortinet | fortios | 6.0.0 – 6.0.10 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for crashes of the FortiClient NAC daemon process (fcnacd) on FortiOS SSL VPN appliances, which may indicate exploitation attempts of this stack-based buffer overflow. ↗
- →Detect anomalously large FortiClient file name values in SSL VPN requests, as the vulnerability is triggered by requesting a large FortiClient file name causing a stack-based buffer overflow. ↗
- ·This vulnerability is only exploitable under non-default FortiOS configuration. Deployments using default settings are not affected. Verify whether the non-default configuration enabling this attack path is present before prioritizing remediation. ↗
- ·Exploitation requires the attacker to be authenticated to the SSL VPN first; unauthenticated remote exploitation is not possible. ↗
- ·No proof-of-concept code achieving remote code execution has been confirmed; the primary confirmed impact is a daemon crash (DoS), with RCE considered theoretical. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8hp7-6mr2-85pv: Under non-default configuration, a stack-based buffer overflow in FortiOS version 6
ghsa_unreviewed·2024-12-19
CVE-2020-12820 [MEDIUM] CWE-121 GHSA-8hp7-6mr2-85pv: Under non-default configuration, a stack-based buffer overflow in FortiOS version 6
Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary code via requesting a large FortiClient file name. We are not aware of proof of concept code successfully achieving the latter.
Fortinet
Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and b...
vendor_fortinet·2024-12-19·CVSS 5.4
CVE-2020-12820 [MEDIUM] CWE-121 Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and b...
FG-IR-20-083: Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and b...
Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary code via requesting a large FortiClient file name. We are not aware of proof of concept code successfully achieving the latter.
CVEs: CVE-2020-12820
CWEs: CWE-121, CWE-787
CVSS: 5.4 (medium)
Affected products: FortiClient, FortiOS
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-12-19
Published