Security Advisory

CVE-2020-15939

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-09-06 15:19:38
Last updated 2024-10-25 13:50:54
Assigner fortinet
CVSS score 4.3
State PUBLISHED

Description

An improper access control vulnerability (CWE-284) in FortiSandbox versions 3.2.1 and below and 3.1.4 and below may allow an authenticated, unprivileged attacker to download the device configuration file via the recovery URL.