Vulnerability record · CVE-2020-9294 · published 27 April 2020
CVE-2020-9294: FortiMail and FortiVoice improper authentication via password change
Fortinet · Fortimail
FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEnterprise 6.0.0 and 6.0.1 contain an improper authentication flaw (CWE-287). A remote attacker can request a password change through the user interface and gain access to the system as a legitimate user without authenticating.
Description
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the user interface.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or user interaction, and a very high EPSS probability make this a top-priority patch despite no KEV listing.
What it is
FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEnterprise 6.0.0 and 6.0.1 contain an improper authentication flaw (CWE-287). A remote attacker can request a password change through the user interface and gain access to the system as a legitimate user without authenticating.
Impact
An unauthenticated attacker can take over a legitimate user account and access the system with that user's privileges, with high impact to confidentiality, integrity and availability per the CVSS vector.
Attack surface
Reachable over the network through the product's user interface with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV and no public exploit or exploitation tags appear in the references, but EPSS is very high at 0.77778 (99.5th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Apply the Fortinet vendor fix referenced in FG-IR-20-045 for the affected FortiMail and FortiVoiceEnterprise versions.
- Restrict management and user interface access to trusted networks or VPN until patching is complete.
- Monitor and alert on password change requests, especially those originating from unauthenticated or unexpected sources.
- Review accounts for unauthorized password changes and reset credentials where compromise is suspected.
- Confirm no unsupported or end-of-life FortiMail or FortiVoiceEnterprise versions remain exposed.
Detection
- Audit logs for password change events on FortiMail and FortiVoiceEnterprise and correlate with source IP and authentication state.
- Alert on user interface requests to password change endpoints that lack a prior successful login.
- Monitor for anomalous logins or account activity following password change events.
- Track external exposure of the affected interfaces and flag unexpected access from untrusted networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.com/psirt/FG-IR-20-045 | Vendor Advisory |
| https://fortiguard.com/psirt/FG-IR-20-045 | Vendor Advisory |
Track CVE-2020-9294 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-9294), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.