CVE-2020-15936

A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and below, version 5.6.13 and below allows attacker to disclose sensitive information via SNI Client Hello TLS packets.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.6 LOW
ADJACENT_NETWORK
HIGH
HIGH
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N
fortinetCNA
2.6 LOW
ADJACENT_NETWORK
HIGH
HIGH
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N/E:X/RL:X/RC:X
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
fortinetfortios
5.6.0 ≤
𝑥
≤ 5.6.13
fortinetfortios
6.0.0 ≤
𝑥
≤ 6.0.11
fortinetfortios
6.2.0 ≤
𝑥
≤ 6.2.5
fortinetfortios
6.4.0 ≤
𝑥
≤ 6.4.3
𝑥
= Vulnerable software versions