CVE-2016-8491: Critical severity Fortinet FortiWLC vulnerability
Published Feb 1, 2017
·Updated
The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.
Affected Software
5 affected components
Fortinet FortiWLC=7.0-9-1
Fortinet FortiWLC=7.0-10-0
Fortinet FortiWLC=8.1-2-0
Fortinet FortiWLC=8.1-3-2
Fortinet FortiWLC=8.2-4-0
Event History
Feb 1, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Data Sourced
via NVD·05:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-8491?
CVE-2016-8491 is considered critical due to the existence of a hardcoded account that can lead to unauthorized access.
2
How do I fix CVE-2016-8491?
To mitigate CVE-2016-8491, users should upgrade Fortinet FortiWLC to a patched version that removes the hardcoded account.
3
Which versions are affected by CVE-2016-8491?
CVE-2016-8491 affects Fortinet FortiWLC versions 7.0-9-1, 7.0-10-0, 8.1-2-0, 8.1-3-2, and 8.2-4-0.
4
What are the risks associated with CVE-2016-8491?
The risks of CVE-2016-8491 include potential unauthorized read/write access to sensitive information and system control.
5
Is there a workaround for CVE-2016-8491?
There are no specific workarounds for CVE-2016-8491; upgrading to a secure version is the recommended solution.