CVE-2019-15712: High severity fortinet fortimail-200d vulnerability
Published Jan 23, 2020
·Updated
An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to access web console they should not be authorized for.
Affected Software
3 affected components
Fortinet FortiMail<=5.4.10
Fortinet FortiMail>=6.0.0<=6.0.6
Fortinet FortiMail=6.2.0
Event History
Jan 23, 2020
CVE Published
via MITRE·05:40 PM
Data Sourced
via MITRE·05:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-15712?
CVE-2019-15712 is an improper access control vulnerability in FortiMail admin webUI.
2
What versions of FortiMail are affected by CVE-2019-15712?
FortiMail versions 6.2.0, 6.0.0 to 6.0.6, and 5.4.10 and below are affected by CVE-2019-15712.
3
How does CVE-2019-15712 affect administrators?
It may allow administrators to access the web console they should not be authorized for.
4
What is the severity of CVE-2019-15712?
CVE-2019-15712 has a severity rating of 7.2, which is considered high.
5
How can I find more information about CVE-2019-15712?
You can find more information about CVE-2019-15712 at the following link: [https://fortiguard.com/advisory/FG-IR-19-237](https://fortiguard.com/advisory/FG-IR-19-237)