Malware Detection Issue in Fortinet FortiOS and FortiClient Products
CVE-2020-9295

4.7MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
17 March 2025

Summary

Fortinet FortiOS and FortiClient have been identified to have a vulnerability where certain malformed or non-standard RAR archives may not be promptly detected, potentially leading to the risk of unrecognized malicious files. Users may experience delayed threat detection, as FortiClient typically recognizes these threats only during extraction through real-time scanning. Similarly, FortiGate appliances will detect such malicious archives only when Virus Outbreak Prevention is activated. This highlights the importance of keeping your security products updated and vigilant against potential threats.

Affected Version(s)

FortiClientWindows 6.2.0 <= 6.2.6

FortiClientWindows 6.0.0 <= 6.0.10

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.