{ "id": "CVE-2020-12818", "sourceIdentifier": "psirt@fortinet.com", "published": "2020-09-24T15:15:13.237", "lastModified": "2020-10-05T14:08:30.270", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker to Fortinet owned IP addresses to go unnoticed." }, { "lang": "es", "value": "Una vulnerabilidad de registro insuficiente en FortiGate versiones anteriores a 6.4.1, puede permitir que el tr\u00e1fico de un atacante no autenticado hacia direcciones IP propiedad de Fortinet pase desapercibido." } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 5.3, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 3.9, "impactScore": 1.4 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 5.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*", "versionEndExcluding": "6.4.1", "matchCriteriaId": "366223BF-F61D-4AC7-A884-D6FB48CD47A7" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_1000d:-:*:*:*:*:*:*:*", "matchCriteriaId": "64F7589C-F20B-4222-B859-78D15C457CE5" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_100e:-:*:*:*:*:*:*:*", "matchCriteriaId": "5E4BAC86-6E1C-4ECE-8E41-789A6A617A40" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_100f:-:*:*:*:*:*:*:*", "matchCriteriaId": "561D84F5-E3D4-4293-AC13-26D2E217D970" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_1100e:-:*:*:*:*:*:*:*", "matchCriteriaId": "648723EC-E144-4975-8D23-A4BB5EF6F07A" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_1500d:-:*:*:*:*:*:*:*", "matchCriteriaId": "D8C8DA5D-9CB6-4BA6-BB8B-F41501726AF9" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_1800f:-:*:*:*:*:*:*:*", "matchCriteriaId": "76792D6F-B647-43A8-8A60-17BE35824BF7" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_2000e:-:*:*:*:*:*:*:*", "matchCriteriaId": "92C3D2D8-A79C-4D10-B72E-D71EA3EB06F4" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_200e:-:*:*:*:*:*:*:*", "matchCriteriaId": "F3D08C3F-51A4-44CF-BB85-A00536FAADAE" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_2200e:-:*:*:*:*:*:*:*", "matchCriteriaId": "0B2A9D43-348B-45DB-94F7-825B29141F09" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_3000d:-:*:*:*:*:*:*:*", "matchCriteriaId": "C79E67E1-8A10-4AD3-A6F5-9E82890216B3" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_3300e:-:*:*:*:*:*:*:*", "matchCriteriaId": "0CCCA9CD-2B75-46AF-989C-C300CB53358E" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_3400e:-:*:*:*:*:*:*:*", "matchCriteriaId": "CD1CDB68-B412-45E2-9AC4-F2A6E5300AA4" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_3600e:-:*:*:*:*:*:*:*", "matchCriteriaId": "5015D2E8-8482-467A-96F4-65CBF0AFAC6E" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_3700d:-:*:*:*:*:*:*:*", "matchCriteriaId": "431E4C52-4BBF-48BA-867B-32D1405A5863" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_3960e:-:*:*:*:*:*:*:*", "matchCriteriaId": "A3E816AC-57B5-4460-AF88-300EB72B5A8A" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_3980e:-:*:*:*:*:*:*:*", "matchCriteriaId": "BF54E933-526F-4E65-A6B1-455389525F27" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_400e:-:*:*:*:*:*:*:*", "matchCriteriaId": "A197765B-E9B4-4E5A-918D-C0C4B679CBA6" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_40f:-:*:*:*:*:*:*:*", "matchCriteriaId": "96C31DB1-CEBD-4796-9CF1-5D9D000A5A9A" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_4200f:-:*:*:*:*:*:*:*", "matchCriteriaId": "326DF840-7BEE-44D3-A8B8-DCE1A673A2C2" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_5001d:-:*:*:*:*:*:*:*", "matchCriteriaId": "B35A82B1-ABA8-493D-9E89-E253CDD10472" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_5001e:-:*:*:*:*:*:*:*", "matchCriteriaId": "922E4449-EB12-444E-9E8C-C67FA537F1BD" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_5001e1:-:*:*:*:*:*:*:*", "matchCriteriaId": "302638DB-0FA0-4804-9FC8-CCD20430B08F" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_5053b:-:*:*:*:*:*:*:*", "matchCriteriaId": "F5B0C1E0-CA41-4A31-A42D-FB25090EC6CB" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_5060:-:*:*:*:*:*:*:*", "matchCriteriaId": "2A78FF2E-986E-439E-A787-0A14E7EE78CC" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_50e:-:*:*:*:*:*:*:*", "matchCriteriaId": "AB3BE8B3-F83D-4C89-AA5C-9B6819128138" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_5144c:-:*:*:*:*:*:*:*", "matchCriteriaId": "20B656F3-C696-48A9-9E1C-6F628E246F48" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_600e:-:*:*:*:*:*:*:*", "matchCriteriaId": "360F94B1-BFBC-455A-84D4-2E5F90DC0E61" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_60e:-:*:*:*:*:*:*:*", "matchCriteriaId": "33F4AB8A-21B9-4969-92B3-250BF7414175" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_60f:-:*:*:*:*:*:*:*", "matchCriteriaId": "2D32F0C5-2949-48B6-B9DD-F070DE11C803" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_6300f:-:*:*:*:*:*:*:*", "matchCriteriaId": "8C87112F-4971-4A57-98E6-8057A758F7E7" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_6500f:-:*:*:*:*:*:*:*", "matchCriteriaId": "4EA7B3B0-C101-406D-AAF4-C7CF86075EA6" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_7040e:-:*:*:*:*:*:*:*", "matchCriteriaId": "68E575C9-D2C9-476B-91BB-D49C6FB62351" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_7060e:-:*:*:*:*:*:*:*", "matchCriteriaId": "1786CFE3-300C-4891-A55F-06BB0D0B67D7" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_80e:-:*:*:*:*:*:*:*", "matchCriteriaId": "68866893-6942-4FF6-88E8-4BEB610AD6FE" }, { "vulnerable": false, "criteria": "cpe:2.3:h:fortinet:fortigate_80f:-:*:*:*:*:*:*:*", "matchCriteriaId": "906455AD-D91C-47D6-A244-33B43ECB0A74" } ] } ] } ], "references": [ { "url": "https://fortiguard.com/advisory/FG-IR-20-033", "source": "psirt@fortinet.com", "tags": [ "Vendor Advisory" ] }, { "url": "https://www.fortiguard.com/psirt/FG-IR-20-033", "source": "nvd@nist.gov", "tags": [ "Vendor Advisory" ] } ] }