{"api_version":"1","generated_at":"2026-07-23T11:20:53+00:00","cve":"CVE-2019-15705","urls":{"html":"https://cve.report/CVE-2019-15705","api":"https://cve.report/api/cve/CVE-2019-15705.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-15705","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-15705"},"summary":{"title":"CVE-2019-15705","description":"An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request.","state":"PUBLIC","assigner":"psirt@fortinet.com","published_at":"2019-11-27 21:15:00","updated_at":"2019-12-16 15:00:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://fortiguard.com/advisory/FG-IR-19-236","name":"https://fortiguard.com/advisory/FG-IR-19-236","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Denial of Service vulnerability impacts the SSL VPN service of FortiOS. | FortiGuard","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-15705","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-15705","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"15705","vulnerable":"1","versionEndIncluding":"6.0.6","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fortinet","cpe5":"fortios","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"15705","vulnerable":"1","versionEndIncluding":"6.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fortinet","cpe5":"fortios","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-15705","qid":"44144","title":"FortiOS Denial of Service (DoS) Vulnerability (FG-IR-19-236)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-15705","ASSIGNER":"psirt@fortinet.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Fortinet","product":{"product_data":[{"product_name":"FortiGate","version":{"version_data":[{"version_value":"FortiOS versions 6.2.1 and below"},{"version_value":"FortiOS versions 6.0.6 and below"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Denial of Service"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://fortiguard.com/advisory/FG-IR-19-236","url":"https://fortiguard.com/advisory/FG-IR-19-236"}]},"description":{"description_data":[{"lang":"eng","value":"An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request."}]}},"nvd":{"publishedDate":"2019-11-27 21:15:00","lastModifiedDate":"2019-12-16 15:00:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*","versionEndIncluding":"6.0.6","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2.0","versionEndIncluding":"6.2.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"15705","Ordinal":"155232","Title":"CVE-2019-15705","CVE":"CVE-2019-15705","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"15705","Ordinal":"1","NoteData":"An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"15705","Ordinal":"2","NoteData":"2019-11-27","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"15705","Ordinal":"3","NoteData":"2019-11-27","Type":"Other","Title":"Modified"}]}}}