Buffer Overflow Vulnerability in FortiOS Products
CVE-2020-12820

8.8HIGH

Key Information:

Vendor
Fortinet
Status
Vendor
CVE Published:
19 December 2024

Summary

CVE-2020-12820 is a high-severity stack-based buffer overflow vulnerability in FortiOS versions 6.0.10 and earlier, as well as 5.6.12 and earlier. When non-default configurations are applied, an authenticated remote attacker exploiting this vulnerability through the SSL VPN can cause the FortiClient NAC daemon (fcnacd) to crash or, potentially, execute arbitrary code by sending a request with an excessively large FortiClient file name. Although there is currently no known proof of concept that successfully demonstrates remote code execution, the risk posed by this flaw warrants immediate attention and remediation measures.

Affected Version(s)

FortiOS 6.0.0 <= 6.0.10

FortiOS 5.6.0 <= 5.6.12

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.