← Vulnerability feed

Vulnerability record · CVE-2020-9294 · published 27 April 2020

CVE-2020-9294: FortiMail and FortiVoice improper authentication via password change

Fortinet · Fortimail

FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEnterprise 6.0.0 and 6.0.1 contain an improper authentication flaw (CWE-287). A remote attacker can request a password change through the user interface and gain access to the system as a legitimate user without authenticating.

9.8 CVSS 3.1 Critical EPSS 78% · top 0.4% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 7.5
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the user interface.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or user interaction, and a very high EPSS probability make this a top-priority patch despite no KEV listing.

What it is

FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEnterprise 6.0.0 and 6.0.1 contain an improper authentication flaw (CWE-287). A remote attacker can request a password change through the user interface and gain access to the system as a legitimate user without authenticating.

Impact

An unauthenticated attacker can take over a legitimate user account and access the system with that user's privileges, with high impact to confidentiality, integrity and availability per the CVSS vector.

Attack surface

Reachable over the network through the product's user interface with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV and no public exploit or exploitation tags appear in the references, but EPSS is very high at 0.77778 (99.5th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Apply the Fortinet vendor fix referenced in FG-IR-20-045 for the affected FortiMail and FortiVoiceEnterprise versions.
  • Restrict management and user interface access to trusted networks or VPN until patching is complete.
  • Monitor and alert on password change requests, especially those originating from unauthenticated or unexpected sources.
  • Review accounts for unauthorized password changes and reset credentials where compromise is suspected.
  • Confirm no unsupported or end-of-life FortiMail or FortiVoiceEnterprise versions remain exposed.

Detection

  • Audit logs for password change events on FortiMail and FortiVoiceEnterprise and correlate with source IP and authentication state.
  • Alert on user interface requests to password change endpoints that lack a prior successful login.
  • Monitor for anomalous logins or account activity following password change events.
  • Track external exposure of the affected interfaces and flag unexpected access from untrusted networks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-9294 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-32756Fortinet FortiMail, FortiNDR, FortiVoice, FortiRecorder, FortiCamera stack buffer overflowA stack-based buffer overflow (CWE-121/CWE-787) in multiple Fortinet products is reachable by sending HTTP requests with a specially crafted hash coo…KEVEPSS 30%analysed9.8CVE-2023-47539Fortinet fortimail improper access control vulnerabilityAn improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a rem…EPSS 1.0%9.8CVE-2021-32586Fortinet fortimail improper input validation vulnerabilityAn improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter …EPSS 1.1%9.8CVE-2021-36166Fortinet fortimail vulnerabilityAn improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's auth…EPSS 1.5%9.8CVE-2021-24007Fortinet fortimail sql injection vulnerabilityMultiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker…EPSS 1.4%9.8CVE-2021-24020Fortinet fortimail improper verification of cryptographic signature vulnerabilityA missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow a…EPSS 0.62%9.1CVE-2024-48885Fortinet fortirecorder path traversal vulnerabilityA improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRe…EPSS 0.79%9.1CVE-2024-48884Fortinet fortimanager path traversal vulnerabilityA improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiMan…EPSS 15%

Source: NIST National Vulnerability Database (record CVE-2020-9294), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.