CVE-2020-15938: High severity fortios vulnerability
When traffic other than HTTP/S (eg: SSH traffic, etc...) traverses the FortiGate in version below 6.2.5 and below 6.4.2 on port 80/443, it is not redirected to the transparent proxy policy for processing, as it doesn't have a valid HTTP header.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15938?
CVE-2020-15938 is a vulnerability in Fortinet FortiOS versions below 6.2.5 and below 6.4.2 that allows non-HTTP/S traffic on port 80/443 to bypass the transparent proxy policy.
How does CVE-2020-15938 impact Fortinet FortiOS?
CVE-2020-15938 impacts Fortinet FortiOS by failing to redirect non-HTTP/S traffic to the transparent proxy policy for processing.
What is the severity of CVE-2020-15938?
CVE-2020-15938 has a severity rating of high, with a score of 7.5.
How can I protect myself from CVE-2020-15938?
To protect yourself from CVE-2020-15938, update your Fortinet FortiOS version to 6.2.5 or above, or 6.4.2 or above.
Where can I find more information about CVE-2020-15938?
You can find more information about CVE-2020-15938 at the following link: https://fortiguard.com/advisory/FG-IR-20-172