Security Advisory

CVE-2020-15939

4.3
MEDIUM

Vulnerability Description

An improper access control vulnerability (CWE-284) in FortiSandbox versions 3.2.1 and below and 3.1.4 and below may allow an authenticated, unprivileged attacker to download the device configuration file via the recovery URL.
Published Date September 6, 2021
Official Source NIST NVD Advisory