Malware Detection Issue in Fortinet FortiOS and FortiClient Products
CVE-2020-9295
4.7MEDIUM
Summary
Fortinet FortiOS and FortiClient have been identified to have a vulnerability where certain malformed or non-standard RAR archives may not be promptly detected, potentially leading to the risk of unrecognized malicious files. Users may experience delayed threat detection, as FortiClient typically recognizes these threats only during extraction through real-time scanning. Similarly, FortiGate appliances will detect such malicious archives only when Virus Outbreak Prevention is activated. This highlights the importance of keeping your security products updated and vigilant against potential threats.
Affected Version(s)
FortiClientWindows 6.2.0 <= 6.2.6
FortiClientWindows 6.0.0 <= 6.0.10
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved