ZeroHour

CVE-2020-15939

CVSS 3.1
4.3 medium
EPSS
<1%p49
Published
()
Modified
Description

An improper access control vulnerability (CWE-284) in FortiSandbox versions 3.2.1 and below and 3.1.4 and below may allow an authenticated, unprivileged attacker to download the device configuration file via the recovery URL.

Vendors
fortinet
Products
fortisandbox
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.