Buffer Overflow Vulnerability in FortiOS Products

CVE-2020-12820

5.4MEDIUM

Key Information

Vendor
Fortinet
Status
FortiOS
Vendor
CVE Published:
19 December 2024

Summary

CVE-2020-12820 is a high-severity stack-based buffer overflow vulnerability in FortiOS versions 6.0.10 and earlier, as well as 5.6.12 and earlier. When non-default configurations are applied, an authenticated remote attacker exploiting this vulnerability through the SSL VPN can cause the FortiClient NAC daemon (fcnacd) to crash or, potentially, execute arbitrary code by sending a request with an excessively large FortiClient file name. Although there is currently no known proof of concept that successfully demonstrates remote code execution, the risk posed by this flaw warrants immediate attention and remediation measures.

Affected Version(s)

FortiOS <= 6.0.10

FortiOS <= 5.6.12

Refferences

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.