CVE-2020-15936

EUVD-2020-7907
A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and below, version 5.6.13 and below allows attacker to disclose sensitive information via SNI Client Hello TLS packets.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.6 LOW
ADJACENT_NETWORK
HIGH
HIGH
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N
fortinetCNA
2.6 LOW
ADJACENT_NETWORK
HIGH
HIGH
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N/E:X/RL:X/RC:X
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
Affected Products (NVD)
VendorProductVersion
fortinetfortios
5.6.0 ≤
𝑥
≤ 5.6.13
fortinetfortios
6.0.0 ≤
𝑥
≤ 6.0.11
fortinetfortios
6.2.0 ≤
𝑥
≤ 6.2.5
fortinetfortios
6.4.0 ≤
𝑥
≤ 6.4.3
𝑥
= Vulnerable software versions