CVE-2020-9294
published 2020-04-27CVE-2020-9294: An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote…
PriorityP186critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
77.78%
99.5th percentile
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the user interface.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortimail | <= 5.4.10 | — |
| fortinet | fortimail | — | — |
| fortinet | fortimail | — | — |
| fortinet | fortimail | — | — |
| fortinet | fortimail | — | — |
| fortinet | fortimail | 6.0.0 – 6.0.7 | — |
| fortinet | fortimail | 6.2.0 – 6.2.2 | — |
| fortinet | fortivoice | — | — |
| fortinet | fortivoice | 6.0.0 – 6.0.1 | — |
| fortinet | fortivoiceenterprise | — | — |
| fortinet | fortivoiceenterprise | — | — |
| fortinet | fortivoiceentreprise | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by monitoring for unauthenticated password change requests via the FortiMail user interface, as this is the attack vector for the login bypass ↗
- →A Metasploit auxiliary scanner module exists for detecting vulnerable FortiMail instances; monitor for scanner activity patterns consistent with this module against FortiMail HTTP endpoints ↗
- →Affected products include FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier, and FortiVoiceEntreprise 6.0.0 and 6.0.1 — alert on unauthenticated sessions gaining authenticated access on these versions ↗
- ·Vulnerability is classified as CWE-287 (Improper Authentication) with a CVSS score of 9.8 (Critical); prioritize patching FortiMail and FortiVoiceEntreprise instances exposed to the internet ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cg58-vw2q-jv22: An improper authentication vulnerability in FortiMail 5
ghsa_unreviewed·2022-05-24
CVE-2020-9294 [HIGH] CWE-287 GHSA-cg58-vw2q-jv22: An improper authentication vulnerability in FortiMail 5
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the user interface.
Fortinet
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 an...
vendor_fortinet·2020-04-27·CVSS 9.8
CVE-2020-9294 [CRITICAL] CWE-287 An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 an...
FG-IR-20-045: An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 an...
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the user interface.
CVEs: CVE-2020-9294
CWEs: CWE-287
CVSS: 9.8 (critical)
Affected products: FortiMail, FortiVoice, FortiVoiceEntreprise
No detection rules found.
No writeups or analysis indexed.
2020-04-27
Published