CVE-2020-15939: Unauthorized user able to download the device configuration file
An improper access control vulnerability (CWE-284) in FortiSandbox may allow an authenticated, unprivileged attacker to download the device configuration file via the recovery URL.
Other sources
An improper access control vulnerability (CWE-284) in FortiSandbox versions 3.2.1 and below and 3.1.4 and below may allow an authenticated, unprivileged attacker to download the device configuration file via the recovery URL.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15939?
CVE-2020-15939 is an improper access control vulnerability (CWE-284) in FortiSandbox versions 3.2.1 and below and 3.1.4 and below.
How does CVE-2020-15939 affect FortiSandbox?
CVE-2020-15939 may allow an authenticated, unprivileged attacker to download the device configuration file via the recovery URL.
What is the severity of CVE-2020-15939?
The severity of CVE-2020-15939 is medium with a CVSS score of 4.3.
Which software versions are affected by CVE-2020-15939?
FortiSandbox versions 3.2.1 and below and 3.1.4 and below are affected by CVE-2020-15939.
How can I fix CVE-2020-15939?
To fix CVE-2020-15939, it is recommended to upgrade FortiSandbox to version 3.1.5 or 3.2.3 or later.