CVE-2020-9294

CRITICAL

An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a...

Affects 2 products across 1 vendor.

CVSS 3.19.8
EPSS77.8%
Percentile100th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-287: Improper Authentication

Software does not prove or insufficiently proves that the user is who they claim to be.

Related Attack Patterns (CAPEC)
CAPEC-57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
via CWE-287
CAPEC-633 Token Impersonation
via CWE-287
CAPEC-650 Upload a Web Shell to a Web Server
via CWE-287
CAPEC-194 Fake the Source of Data
via CWE-287
CAPEC-593 Session Hijacking
via CWE-287
Show all 10

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A critical improper authentication vulnerability in specific versions of FortiMail and FortiVoiceEnterprise allows unauthenticated attackers to gain unauthorized access by requesting a password change.

BSID: BS-2020-GLOBAL-186058-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2020-9294?
A critical improper authentication vulnerability in specific versions of FortiMail and FortiVoiceEnterprise allows unauthenticated attackers to gain unauthorized access by requesting a password change.
What is the CVSS score for CVE-2020-9294?
CVE-2020-9294 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 77.8%.
Is CVE-2020-9294 actively exploited?
No confirmed active exploitation of CVE-2020-9294 as of 2026-09-25.
How do I remediate CVE-2020-9294?
Priority: IMMEDIATE. Advisory: https://fortiguard.com/psirt/FG-IR-20-045 PSIRT: [email protected]
What systems are affected by CVE-2020-9294?
CVE-2020-9294 affects: Fortinet, Fortinet.
Vulnerability Details
CVE IDCVE-2020-9294
BSIDBS-2020-GLOBAL-186058-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2020-04-27
Last Modified2026-06-17
ICS Relevance70%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the user interface.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability exists in the user interface of FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier, and FortiVoiceEnterprise 6.0.0 and 6.0.1. An attacker can exploit this by sending a password change request, which could lead to unauthorized access as a legitimate user.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductAffected Versions
Fortinet Fortimail 5.4.10 6.0.7
Fortinet Fortivoice ≥ 6.0.0, ≤ 6.0.1
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 2352 Days
CISA known-exploitedNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hasha0bd17981921b03bc6267b52b5886232d7dcaeeed5cb0ca9816f0103c71deb27e6fe9e6929536b5385b617e39c3fc6338f579c14335317a7e6beac2f79bf088e
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2026-26084 9.9 A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 throug... CVE-2017-17539 9.8 The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier a... CVE-2018-13379 9.8 An Improper Limitation of a Pathname to a Restricted Directory ("Path Travers... CVE-2021-32588 9.8 A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versio...
View all Fortinet CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →