CVE-2017-17540: Critical severity fortinet fortiwlc vulnerability
Published May 7, 2018
·Updated
The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell.
Affected Software
2 affected components
Fortinet FortiWLC>=7.0<=7.0.11
Fortinet FortiWLC>=8.0<=8.3.3
Event History
May 7, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-17540?
CVE-2017-17540 has a medium severity due to the potential for unauthorized access to sensitive information and system controls.
2
How do I fix CVE-2017-17540?
To fix CVE-2017-17540, update the Fortinet FortiWLC to a version beyond 8.3.3 or apply the recommended patches from Fortinet.
3
What types of access does CVE-2017-17540 allow?
CVE-2017-17540 allows attackers to gain unauthorized read/write access via a remote shell.
4
Which versions of Fortinet FortiWLC are affected by CVE-2017-17540?
CVE-2017-17540 affects Fortinet FortiWLC versions from 7.0 to 8.3.3 inclusive.
5
Who can be impacted by CVE-2017-17540?
Any organization using vulnerable versions of Fortinet FortiWLC could be impacted by CVE-2017-17540 due to the risk of unauthorized access.