CVE-2020-15938: Fortinet FortiOS

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

When traffic other than HTTP/S (eg: SSH traffic, etc...) traverses the FortiGate in version below 6.2.5 and below 6.4.2 on port 80/443, it is not redirected to the transparent proxy policy for processing, as it doesn't have a valid HTTP header.

Affected products

  • Fortinet FortiOS: up to and including 6.2.5; from 6.4.0, up to and including 6.4.2

Published 2021-03-04. Last modified 2026-06-17.