Lucene search

K
cveFortinetCVE-2020-12818
HistorySep 24, 2020 - 3:15 p.m.

CVE-2020-12818

2020-09-2415:15:13
fortinet
web.nvd.nist.gov
49
cve-2020-12818
insufficient logging
vulnerability
fortigate
fortinet
unauthenticated attacker
ip addresses
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

38.5%

An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker to Fortinet owned IP addresses to go unnoticed.

Affected configurations

Nvd
Node
fortinetfortiosRange<6.4.1
AND
fortinetfortigate_1000dMatch-
OR
fortinetfortigate_100eMatch-
OR
fortinetfortigate_100fMatch-
OR
fortinetfortigate_1100eMatch-
OR
fortinetfortigate_1500dMatch-
OR
fortinetfortigate_1800fMatch-
OR
fortinetfortigate_2000eMatch-
OR
fortinetfortigate_200eMatch-
OR
fortinetfortigate_2200eMatch-
OR
fortinetfortigate_3000dMatch-
OR
fortinetfortigate_3300eMatch-
OR
fortinetfortigate_3400eMatch-
OR
fortinetfortigate_3600eMatch-
OR
fortinetfortigate_3700dMatch-
OR
fortinetfortigate_3960eMatch-
OR
fortinetfortigate_3980eMatch-
OR
fortinetfortigate_400eMatch-
OR
fortinetfortigate_40fMatch-
OR
fortinetfortigate_4200fMatch-
OR
fortinetfortigate_5001dMatch-
OR
fortinetfortigate_5001eMatch-
OR
fortinetfortigate_5001e1Match-
OR
fortinetfortigate_5053bMatch-
OR
fortinetfortigate_5060Match-
OR
fortinetfortigate_50eMatch-
OR
fortinetfortigate_5144cMatch-
OR
fortinetfortigate_600eMatch-
OR
fortinetfortigate_60eMatch-
OR
fortinetfortigate_60fMatch-
OR
fortinetfortigate_6300fMatch-
OR
fortinetfortigate_6500fMatch-
OR
fortinetfortigate_7040eMatch-
OR
fortinetfortigate_7060eMatch-
OR
fortinetfortigate_80eMatch-
OR
fortinetfortigate_80fMatch-
VendorProductVersionCPE
fortinetfortios*cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
fortinetfortigate_1000d-cpe:2.3:h:fortinet:fortigate_1000d:-:*:*:*:*:*:*:*
fortinetfortigate_100e-cpe:2.3:h:fortinet:fortigate_100e:-:*:*:*:*:*:*:*
fortinetfortigate_100f-cpe:2.3:h:fortinet:fortigate_100f:-:*:*:*:*:*:*:*
fortinetfortigate_1100e-cpe:2.3:h:fortinet:fortigate_1100e:-:*:*:*:*:*:*:*
fortinetfortigate_1500d-cpe:2.3:h:fortinet:fortigate_1500d:-:*:*:*:*:*:*:*
fortinetfortigate_1800f-cpe:2.3:h:fortinet:fortigate_1800f:-:*:*:*:*:*:*:*
fortinetfortigate_2000e-cpe:2.3:h:fortinet:fortigate_2000e:-:*:*:*:*:*:*:*
fortinetfortigate_200e-cpe:2.3:h:fortinet:fortigate_200e:-:*:*:*:*:*:*:*
fortinetfortigate_2200e-cpe:2.3:h:fortinet:fortigate_2200e:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 361

CNA Affected

[
  {
    "product": "Fortinet FortiOS",
    "vendor": "Fortinet",
    "versions": [
      {
        "status": "affected",
        "version": "FortiOS before 6.4.1"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

38.5%

Related for CVE-2020-12818