CVE-2020-15942: Fortinet FortiWeb
Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.
An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may allow a remote authenticated attacker to read the password used by the FortiWeb scanner to access the device defined in the scan profile.
Affected products
- Fortinet FortiWeb: from 6.2.0, up to and including 6.2.3; from 6.3.0, up to and including 6.3.4
Published 2021-04-12. Last modified 2026-06-17.