CVE-2020-29010 - CVE House
Back to Database
Status published Medium CVE-2020-29010

An exposure of sensitive information to an unauthorized actor vulnerability...

Vulnerability Description

An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to read the SSL VPN events log entries of users in other VDOMs by executing "get vpn ssl monitor" from the CLI. The sensitive data includes usernames, user groups, and IP address.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-29010

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

FortiOS
Vulnerable Versions:
6.2.1, 6.0.0

Timeline

Official Publish: March 17th, 2025
Last Modified: March 17th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N/E:F/RL:X/RC:X

Weaknesses (CWE)