Vulnerability Details CVE-2020-29017
An OS command injection vulnerability in FortiDeceptor 3.1.0, 3.0.1, 3.0.0 may allow a remote authenticated attacker to execute arbitrary commands on the system by exploiting a command injection vulnerability on the Customization page.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.051
EPSS Ranking 89.2%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
Products affected by CVE-2020-29017
-
cpe:2.3:a:fortinet:fortideceptor:3.0.0
-
cpe:2.3:a:fortinet:fortideceptor:3.0.1
-
cpe:2.3:a:fortinet:fortideceptor:3.1.0