cbcvebase.
CVE-2020-12820
published 2024-12-19

CVE-2020-12820: Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker…

PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.86%
54.3th percentile
Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary code via requesting a large FortiClient file name. We are not aware of proof of concept code successfully achieving the latter.

Affected

6 ranges
VendorProductVersion rangeFixed in
fortinetforticlient
fortinetfortios< 5.6.135.6.13
fortinetfortios
fortinetfortios5.6.0 – 5.6.12
fortinetfortios>= 6.0.0 < 6.0.116.0.11
fortinetfortios6.0.0 – 6.0.10

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for crashes of the FortiClient NAC daemon process (fcnacd) on FortiOS SSL VPN appliances, which may indicate exploitation attempts of this stack-based buffer overflow.
  • Detect anomalously large FortiClient file name values in SSL VPN requests, as the vulnerability is triggered by requesting a large FortiClient file name causing a stack-based buffer overflow.
  • ·This vulnerability is only exploitable under non-default FortiOS configuration. Deployments using default settings are not affected. Verify whether the non-default configuration enabling this attack path is present before prioritizing remediation.
  • ·Exploitation requires the attacker to be authenticated to the SSL VPN first; unauthenticated remote exploitation is not possible.
  • ·No proof-of-concept code achieving remote code execution has been confirmed; the primary confirmed impact is a daemon crash (DoS), with RCE considered theoretical.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.