CVE-2020-15938: Fortinet FortiOS
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
When traffic other than HTTP/S (eg: SSH traffic, etc...) traverses the FortiGate in version below 6.2.5 and below 6.4.2 on port 80/443, it is not redirected to the transparent proxy policy for processing, as it doesn't have a valid HTTP header.
Affected products
- Fortinet FortiOS: up to and including 6.2.5; from 6.4.0, up to and including 6.4.2
Published 2021-03-04. Last modified 2026-06-17.