CVE-2020-6641
published 2021-06-02CVE-2020-6641: Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2.1.0 administration interface may allow an attacker to gain…
PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.59%
44.3th percentile
Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2.1.0 administration interface may allow an attacker to gain access to some user data via portal manager or portal users parameters.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortinet_fortipresence | — | — |
| fortinet | fortipresence | < 20.1 | 20.1 |
| fortinet | fortipresence | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2.1.0 administration...
vendor_fortinet·2021-06-02·CVSS 4.3
CVE-2020-6641 [MEDIUM] CWE-639 Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2.1.0 administration...
FG-IR-19-258: Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2.1.0 administration...
Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2.1.0 administration interface may allow an attacker to gain access to some user data via portal manager or portal users parameters.
CVEs: CVE-2020-6641
CWEs: CWE-639
CVSS: 4.3 (medium)
Affected products: FortiPresence, Fortinet
GHSA
GHSA-jxf8-g6gq-m62f: Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2
ghsa_unreviewed·2022-05-24
CVE-2020-6641 [MEDIUM] CWE-639 GHSA-jxf8-g6gq-m62f: Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2
Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2.1.0 administration interface may allow an attacker to gain access to some user data via portal manager or portal users parameters.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-06-02
Published