CVE-2016-4966: Medium severity fortinet fortiwan vulnerability
Published Sep 21, 2016
·Updated
The diagnosiscontrol.php page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to download PCAP files via vectors related to the UserName GET parameter.
Affected Software
1 affected component
Fortinet FortiWan<=4.2.4
Event History
Sep 21, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4966?
CVE-2016-4966 is categorized as a medium severity vulnerability.
2
How do I fix CVE-2016-4966?
To fix CVE-2016-4966, upgrade Fortinet FortiWan to version 4.2.5 or later.
3
Who is affected by CVE-2016-4966?
CVE-2016-4966 affects remote authenticated users of Fortinet FortiWan versions up to and including 4.2.4.
4
What type of vulnerability is CVE-2016-4966?
CVE-2016-4966 is a remote code execution vulnerability that allows unauthorized downloads of PCAP files.
5
What is the impact of exploiting CVE-2016-4966?
Exploitation of CVE-2016-4966 could lead to exposure of sensitive network traffic captured in PCAP files.