CVE-2020-9295 describes a vulnerability in FortiOS and FortiClient where certain malformed or non-standard RAR archives, potentially containing malicious files, may not be immediately detected by the antivirus engine. This affects FortiOS 6.2 (AV engine 6.00142 and below), FortiOS 6.4 (AV engine 6.00144 and below), and FortiClient 6.2 (AV engine 6.00137 and below). The vulnerability has a CVSS score of 7.5 (High), indicating a network-based attack with low complexity and no user interaction required, potentially leading to high availability impact. However, real-time scanning during extraction or enabling Virus Outbreak Prevention can detect the malicious content. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.00145CPE matchmatch criteria | cpe:2.3:a:fortinet:antivirus_engine:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.