CVE-2020-15938
FortiOS vulnerability analysis and mitigation

Overview

CVE-2020-15938 affects FortiOS versions 6.4.2 and below, and versions 6.2.5 and below. The vulnerability occurs when traffic other than HTTP/S (e.g., SSH traffic) traverses the FortiGate on port 80/443, where it is not redirected to the transparent proxy policy for processing due to the absence of a valid HTTP header (Fortiguard Advisory, NVD).

Technical details

The vulnerability has received varying CVSS severity scores from different sources. Fortinet assigned it a CVSS v3.1 Base Score of 4.0 (MEDIUM) with vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N, while NIST NVD rated it with a Base Score of 7.5 (HIGH) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N (NVD).

Impact

The vulnerability results in improper access control, potentially allowing non-HTTP/S traffic to bypass intended security controls when transparent proxy is enabled (Fortiguard Advisory).

Exploitability

The vulnerability requires network access and can be exploited without authentication or user interaction. However, there are differing assessments of the attack complexity, with Fortinet indicating it as high and NIST NVD rating it as low (NVD).

Mitigation and workarounds

Fortinet recommends upgrading to FortiOS version 6.4.3 or above. Alternative workarounds include disabling the tunnel-non-http setting to block invalid HTTP traffic on port 80, and setting the unsupported-ssl option to 'block' for port 443 in the firewall ssl-ssh-profile configuration (Fortiguard Advisory).

Additional resources


SourceThis report was generated using AI

Related FortiOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71407MEDIUM5.6
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NoYesAug 12, 2026
CVE-2026-59839MEDIUM5.5
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026
CVE-2026-71408MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NoYesAug 12, 2026
CVE-2026-70466MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiweb
NoYesAug 12, 2026
CVE-2026-59840MEDIUM4.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management