cbcvebase.
CVE-2020-9294
published 2020-04-27

CVE-2020-9294: An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote…

PriorityP186critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
77.78%
99.5th percentile
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the user interface.

Affected

12 ranges
VendorProductVersion rangeFixed in
fortinetfortimail<= 5.4.10
fortinetfortimail
fortinetfortimail
fortinetfortimail
fortinetfortimail
fortinetfortimail6.0.0 – 6.0.7
fortinetfortimail6.2.0 – 6.2.2
fortinetfortivoice
fortinetfortivoice6.0.0 – 6.0.1
fortinetfortivoiceenterprise
fortinetfortivoiceenterprise
fortinetfortivoiceentreprise

Detection & IOCsextracted from sources · hover to see the quote

  • Detect exploitation attempts by monitoring for unauthenticated password change requests via the FortiMail user interface, as this is the attack vector for the login bypass
  • A Metasploit auxiliary scanner module exists for detecting vulnerable FortiMail instances; monitor for scanner activity patterns consistent with this module against FortiMail HTTP endpoints
  • Affected products include FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier, and FortiVoiceEntreprise 6.0.0 and 6.0.1 — alert on unauthenticated sessions gaining authenticated access on these versions
  • ·Vulnerability is classified as CWE-287 (Improper Authentication) with a CVSS score of 9.8 (Critical); prioritize patching FortiMail and FortiVoiceEntreprise instances exposed to the internet

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.