CVE-2020-15935: Medium severity fortinet fortiadc vulnerability
A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0 and below may allow a remote authenticated attacker to retrieve some sensitive information such as users LDAP passwords and RADIUS shared secret by deobfuscating the passwords entry fields.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-15935.
What is the severity of CVE-2020-15935?
The severity of CVE-2020-15935 is medium with a CVSS score of 4.3.
What is the affected software version range for CVE-2020-15935?
FortiADC versions 5.4.3 and below, 6.0.0 and below are affected.
How can a remote attacker exploit CVE-2020-15935?
A remote authenticated attacker can exploit CVE-2020-15935 by deobfuscating the passwords entry fields in the GUI and retrieving sensitive information such as LDAP passwords and RADIUS shared secret.
Is there a fix available for CVE-2020-15935?
Yes, Fortinet has released a fix for CVE-2020-15935. It is recommended to update to a version that is not affected.