CVE-2019-15707: Medium severity fortinet fortimail-200d vulnerability
Published Jan 23, 2020
·Updated
An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to perform system backup config download they should not be authorized for.
Affected Software
3 affected components
Fortinet FortiMail<=5.4.10
Fortinet FortiMail>=6.0.0<=6.0.6
Fortinet FortiMail=6.2.0
Event History
Jan 23, 2020
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-15707?
CVE-2019-15707 is an improper access control vulnerability in FortiMail admin webUI.
2
Which versions of FortiMail are affected by CVE-2019-15707?
FortiMail versions 6.2.0, 6.0.0 to 6.0.6, and 5.4.10 and below are affected by CVE-2019-15707.
3
What can an attacker do with CVE-2019-15707?
An attacker can perform unauthorized system backup config download using CVE-2019-15707.
4
How severe is CVE-2019-15707?
CVE-2019-15707 has a severity score of 4.9, which is considered medium severity.
5
How can I fix CVE-2019-15707?
To fix CVE-2019-15707, it is recommended to update FortiMail to a version that is not affected or apply any patches provided by the vendor.