CVE-2016-4967: Infoleak
Published Sep 21, 2016
·Updated
Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to obtain sensitive information from (1) a backup of the device configuration via script/cfgshow.php or (2) PCAP files via script/system/tcpdump.php.
Affected Software
1 affected component
Fortinet FortiWan<=4.2.4
Event History
Sep 21, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4967?
CVE-2016-4967 is considered a medium severity vulnerability due to the potential for sensitive information disclosure.
2
How do I fix CVE-2016-4967?
To fix CVE-2016-4967, upgrade Fortinet FortiWan to version 4.2.5 or later.
3
What kind of sensitive information can be exposed by CVE-2016-4967?
CVE-2016-4967 can expose device configuration backups and PCAP files containing network traffic.
4
Who is affected by CVE-2016-4967?
CVE-2016-4967 affects remote authenticated users of Fortinet FortiWan versions prior to 4.2.5.
5
What actions should be taken if I am using a vulnerable version associated with CVE-2016-4967?
If using a vulnerable version, it is recommended to update the software immediately to mitigate the risk of information disclosure.