CVE-2020-12819 - CVE House
Back to Database
Status published Medium CVE-2020-12819

A heap-based buffer overflow vulnerability in the processing of Link...

Vulnerability Description

A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier may allow a remote attacker with valid SSL VPN credentials to crash the SSL VPN daemon by sending a large LCP packet, when tunnel mode is enabled. Arbitrary code execution may be theoretically possible, albeit practically very difficult to achieve in this context

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-12819

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

FortiOS
Vulnerable Versions:
6.4.0, 6.2.0, 6.0.0, 5.6.0

Timeline

Official Publish: December 19th, 2024
Last Modified: December 20th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:U/RL:X/RC:X

Weaknesses (CWE)