VYPR
Medium severity5.4NVD Advisory· Published Dec 19, 2024· Updated Jun 17, 2026

CVE-2020-12820

CVE-2020-12820

Description

Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary code via requesting a large FortiClient file name. We are not aware of proof of concept code successfully achieving the latter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Fortinet/Fortios3 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: <5.6.13
    • cpe:2.3:o:fortinet:fortios:6.0.10:*:*:*:*:*:*:*range: 6.0.0
    • (no CPE)range: <=6.0.10, <=5.6.12

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.