CVE-2020-15936: Input Validation
A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and below, version 5.6.13 and below allows attacker to disclose sensitive information via SNI Client Hello TLS packets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-15936?
The severity of CVE-2020-15936 is classified as medium as it allows attackers to disclose sensitive information.
How do I fix CVE-2020-15936?
To fix CVE-2020-15936, upgrade FortiGate to versions 6.4.4 or above, 6.2.6 or above, 6.0.12 or above, and 5.6.14 or above.
Which FortiGate versions are affected by CVE-2020-15936?
FortiGate versions 5.6.0 through 5.6.13, 6.0.0 through 6.0.11, 6.2.0 through 6.2.5, and 6.4.0 through 6.4.3 are affected by CVE-2020-15936.
What type of vulnerability is CVE-2020-15936?
CVE-2020-15936 is an improper input validation vulnerability that can lead to sensitive information disclosure.
Can CVE-2020-15936 be exploited remotely?
Yes, CVE-2020-15936 can be exploited remotely through SNI Client Hello TLS packets.