CVE-2019-15712

EUVD-2019-6648
An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to access web console they should not be authorized for.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
Affected Products (NVD)
VendorProductVersion
fortinetfortimail
𝑥
≤ 5.4.10
fortinetfortimail
6.0.0 ≤
𝑥
≤ 6.0.6
fortinetfortimail
6.2.0
𝑥
= Vulnerable software versions