Description
An improper access control vulnerability (CWE-284) in FortiSandbox versions 3.2.1 and below and 3.1.4 and below may allow an authenticated, unprivileged attacker to download the device configuration file via the recovery URL.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-7910 | An improper access control vulnerability (CWE-284) in FortiSandbox versions 3.2.1 and below and 3.1.4 and below may allow an authenticated, unprivileged attacker to download the device configuration file via the recovery URL. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/advisory/FG-IR-20-071 |
|
History
Fri, 25 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-25T13:50:54.036Z
Reserved: 2020-07-24T00:00:00.000Z
Link: CVE-2020-15939
Updated: 2024-08-04T13:30:23.284Z
Status : Modified
Published: 2021-09-06T16:15:07.373
Modified: 2024-11-21T05:06:29.773
Link: CVE-2020-15939
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD