2025-03-23 03:03:54 +00:00

60 lines
2.4 KiB
JSON

{
"id": "CVE-2020-9295",
"sourceIdentifier": "psirt@fortinet.com",
"published": "2025-03-17T14:15:16.903",
"lastModified": "2025-03-17T14:15:16.903",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version 6.00137 and below may not immediately detect certain types of malformed or non-standard RAR archives, potentially containing malicious files. Based on the samples provided, FortiClient will detect the malicious files upon trying extraction by real-time scanning and FortiGate will detect the malicious archive if Virus Outbreak Prevention is enabled."
},
{
"lang": "es",
"value": "Es posible que FortiOS 6.2 con motor antivirus versi\u00f3n 6.00142 o inferior, FortiOS 6.4 con motor antivirus versi\u00f3n 6.00144 o inferior y FortiClient 6.2 con motor antivirus versi\u00f3n 6.00137 o inferior no detecten inmediatamente ciertos tipos de archivos RAR malformados o no est\u00e1ndar que podr\u00edan contener archivos maliciosos. Con base en las muestras proporcionadas, FortiClient detectar\u00e1 los archivos maliciosos al intentar extraerlos mediante an\u00e1lisis en tiempo real y FortiGate detectar\u00e1 el archivo malicioso si la Prevenci\u00f3n de Brotes de Virus est\u00e1 activada."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "psirt@fortinet.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N",
"baseScore": 4.7,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.8,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "psirt@fortinet.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-358"
}
]
}
],
"references": [
{
"url": "https://fortiguard.com/psirt/FG-IR-20-037",
"source": "psirt@fortinet.com"
}
]
}