CVE-2020-15936: Fortinet FortiOS
Medium severity, CVSS 4.5. EPSS: 0.7% chance of exploitation in the next 30 days.
A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and below, version 5.6.13 and below allows attacker to disclose sensitive information via SNI Client Hello TLS packets.
Affected products
- Fortinet FortiOS: from 5.6.0, up to and including 5.6.13; from 6.0.0, up to and including 6.0.11; from 6.2.0, up to and including 6.2.5; from 6.4.0, up to and including 6.4.3
Published 2022-03-01. Last modified 2026-06-17.