Improper Access Control in FortiSandbox by Fortinet
CVE-2020-15939
4.3MEDIUM
What is CVE-2020-15939?
An improper access control vulnerability in FortiSandbox versions 3.2.1 and earlier, as well as 3.1.4 and earlier, could potentially enable an authenticated, but unprivileged, attacker to exploit the system. By accessing a recovery URL, the attacker may be able to download sensitive device configuration files, which could lead to further security risks and unauthorized access.
Affected Version(s)
Fortinet FortiSandbox FortiSandbox 3.2.1, 3.1.4