CVE-2016-7560: Critical severity fortinet fortiwlc vulnerability
The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which allows remote attackers to read or write to arbitrary files via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7560?
CVE-2016-7560 is considered to be of medium severity due to its potential to allow unauthorized access to system files.
How do I fix CVE-2016-7560?
To fix CVE-2016-7560, update your FortiWLC to the latest version where the hardcoded rsync account issue is resolved.
What impact does CVE-2016-7560 have on affected systems?
CVE-2016-7560 allows remote attackers to read or write to arbitrary files, posing a significant risk to data integrity and confidentiality.
Which versions of FortiWLC are affected by CVE-2016-7560?
CVE-2016-7560 affects Fortinet FortiWLC versions up to and including 6.1-2-29 and several specified later versions.
Is there a workaround for CVE-2016-7560 while awaiting a patch?
Currently, disabling the rsync service may serve as a temporary workaround to mitigate the risks posed by CVE-2016-7560.