CVE-2020-15941: Path Traversal
A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authenticated attacker to inject directory traversal character sequences to add/delete the files of the server via the name parameter of Deployment Packages.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15941?
CVE-2020-15941 is a path traversal vulnerability in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below.
What is the severity of CVE-2020-15941?
The severity of CVE-2020-15941 is medium with a CVSS score of 5.4.
How does CVE-2020-15941 affect FortiClientEMS?
CVE-2020-15941 may allow an authenticated attacker to inject directory traversal sequences and manipulate files on the server via the name parameter of Deployment Packages.
Which versions of FortiClientEMS are affected by CVE-2020-15941?
FortiClientEMS versions 6.4.1 and below, and 6.2.8 and below are affected by CVE-2020-15941.
How can I fix CVE-2020-15941?
Update FortiClientEMS to version 6.4.2 or above, or version 6.2.9 or above to mitigate CVE-2020-15941.