First published: Mon May 07 2018(Updated: )
The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiWLC | >=7.0<=7.0.11 | |
Fortinet FortiWLC | >=8.0<=8.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17540 has a medium severity due to the potential for unauthorized access to sensitive information and system controls.
To fix CVE-2017-17540, update the Fortinet FortiWLC to a version beyond 8.3.3 or apply the recommended patches from Fortinet.
CVE-2017-17540 allows attackers to gain unauthorized read/write access via a remote shell.
CVE-2017-17540 affects Fortinet FortiWLC versions from 7.0 to 8.3.3 inclusive.
Any organization using vulnerable versions of Fortinet FortiWLC could be impacted by CVE-2017-17540 due to the risk of unauthorized access.