CVE-2015-3293: Fortinet FortiMail

Medium severity, CVSS 4.0. EPSS: 1% chance of exploitation in the next 30 days.

FortiMail 5.0.3 through 5.2.3 allows remote administrators to obtain credentials via the "diag debug application httpd" command.

Affected products

  • Fortinet FortiMail: version 5.0.3 only; version 5.0.4 only; version 5.0.5 only; version 5.0.6 only; version 5.0.7 only; version 5.1 only; …

Published 2015-04-14. Last modified 2026-06-17.