PT-2015-3364 · Fortinet · Fortios

Publicado

2015-10-15

·

Atualizado

2016-12-03

·

CVE-2015-7361

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiOS version 5.2.3
Description The issue is related to errors in the authentication mechanism of FortiOS. When configured to use High Availability (HA) and the dedicated management interface is enabled, it does not require authentication for access to the ZebOS shell on the HA dedicated management interface. This allows remote attackers to obtain shell access, potentially leading to unauthorized access.
Recommendations For FortiOS version 5.2.3, consider disabling the dedicated management interface until a patch is available to prevent unauthorized access to the ZebOS shell. Restrict access to the HA dedicated management interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-01293
CVE-2015-7361

Produtos afetados

Fortios