CVE-2020-9295

FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version 6.00137 and below may not immediately detect certain types of malformed or non-standard RAR archives, potentially containing malicious files. Based on the samples provided, FortiClient will detect the malicious files upon trying extraction by real-time scanning and FortiGate will detect the malicious archive if Virus Outbreak Prevention is enabled.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-20-037 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:fortinet:antivirus_engine:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:fortinet:antivirus_engine:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*

History

No history.

Information

Published : 2025-03-17 14:15

Updated : 2025-08-14 21:11


NVD link : CVE-2020-9295

Mitre link : CVE-2020-9295

CVE.ORG link : CVE-2020-9295


JSON object : View

Products Affected

fortinet

  • forticlient
  • fortios
  • antivirus_engine
CWE
CWE-358

Improperly Implemented Security Check for Standard