CVE-2020-12820: Buffer Overflow
Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary code via requesting a large FortiClient file name. We are not aware of proof of concept code successfully achieving the latter.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12820?
CVE-2020-12820 is classified as a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2020-12820?
To fix CVE-2020-12820, upgrade FortiOS to version 6.0.11 or 5.6.13 or later.
What can an attacker do with CVE-2020-12820?
An authenticated attacker can exploit CVE-2020-12820 to crash the FortiClient NAC daemon and could potentially execute arbitrary code.
Which versions of FortiOS are affected by CVE-2020-12820?
CVE-2020-12820 affects FortiOS versions 6.0.10 and below, as well as 5.6.12 and below.
Is CVE-2020-12820 related to SSL VPN access?
Yes, CVE-2020-12820 can be exploited by attackers authenticated to the SSL VPN.