CVE-2020-15935
published 2021-11-02CVE-2020-15935: A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve…
PriorityP419medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.53%
40.9th percentile
A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and RADIUS shared secret by deobfuscating the passwords entry fields.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiadc | — | — |
| fortinet | fortiadc | 5.0.0 – 5.4.3 | — |
| fortinet | fortiadc | 6.0.0 – 6.0.1 | — |
| fortinet | fortinet_fortiadc | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a re...
vendor_fortinet·2021-11-02·CVSS 4.3
CVE-2020-15935 [MEDIUM] CWE-312 A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a re...
FG-IR-20-044: A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a re...
A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and RADIUS shared secret by deobfuscating the passwords entry fields.
CVEs: CVE-2020-15935
CWEs: CWE-312
CVSS: 4.3 (medium)
Affected products: FortiADC
GHSA
GHSA-j26f-vqgh-5h66: A cleartext storage of sensitive information in GUI in FortiADC versions 5
ghsa_unreviewed·2022-05-24
CVE-2020-15935 [MEDIUM] CWE-312 GHSA-j26f-vqgh-5h66: A cleartext storage of sensitive information in GUI in FortiADC versions 5
A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and RADIUS shared secret by deobfuscating the passwords entry fields.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-11-02
Published