PT-2015-3364 · Fortinet · Fortios
Publicado
2015-10-15
·
Atualizado
2016-12-03
·
CVE-2015-7361
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FortiOS version 5.2.3
Description
The issue is related to errors in the authentication mechanism of FortiOS. When configured to use High Availability (HA) and the dedicated management interface is enabled, it does not require authentication for access to the ZebOS shell on the HA dedicated management interface. This allows remote attackers to obtain shell access, potentially leading to unauthorized access.
Recommendations
For FortiOS version 5.2.3, consider disabling the dedicated management interface until a patch is available to prevent unauthorized access to the ZebOS shell. Restrict access to the HA dedicated management interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fortios