CVE-2016-1909: Critical severity fortios vulnerability
Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for the FortimanagerAccess account, which allows remote attackers to obtain administrative access via an SSH session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1909?
CVE-2016-1909 is classified as a high severity vulnerability due to the presence of a hardcoded passphrase that compromises system security.
How do I fix CVE-2016-1909?
To remediate CVE-2016-1909, upgrade the Fortinet FortiOS, FortiAnalyzer, FortiSwitch, or FortiCache to the latest recommended version that addresses this vulnerability.
Which Fortinet software versions are affected by CVE-2016-1909?
CVE-2016-1909 affects multiple versions including FortiOS versions prior to 4.1.11, 4.2.16, 4.3.17, and all versions of 5.0 prior to 5.0.8.
What impact does CVE-2016-1909 have on security?
CVE-2016-1909 allows potential unauthorized access to the Fortimanager_Access account, leading to elevated privileges and possible system compromise.
Is CVE-2016-1909 widely exploitable?
Yes, CVE-2016-1909 is considered widely exploitable due to the nature of the hardcoded passphrase being accessible to attackers.