Buffer Overflow Vulnerability in FortiOS Products
CVE-2020-12820
5.4MEDIUM
Summary
CVE-2020-12820 is a high-severity stack-based buffer overflow vulnerability in FortiOS versions 6.0.10 and earlier, as well as 5.6.12 and earlier. When non-default configurations are applied, an authenticated remote attacker exploiting this vulnerability through the SSL VPN can cause the FortiClient NAC daemon (fcnacd) to crash or, potentially, execute arbitrary code by sending a request with an excessively large FortiClient file name. Although there is currently no known proof of concept that successfully demonstrates remote code execution, the risk posed by this flaw warrants immediate attention and remediation measures.
Affected Version(s)
FortiOS <= 6.0.10
FortiOS <= 5.6.12
Refferences
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database