CVSS v3
9.8
CRITICAL
EPSS Score
80.1 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the user interface.
Technical details
- Published
- 2020-04-27
Frequently asked questions
What is CVE-2020-9294?
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the user interface.
Is CVE-2020-9294 actively exploited?
Active exploitation of CVE-2020-9294 has not been confirmed. The EPSS score is 80.1%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2020-9294?
CVE-2020-9294 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Is CVE-2020-9294 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2020 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).