CVE-2017-7336: Critical severity fortinet fortiwlm mea for fortimanager vulnerability
Published Jul 22, 2017
·Updated
A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges.
Affected Software
1 affected component
Fortinet FortiWLM<=8.3.0
Event History
Jul 22, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7336?
CVE-2017-7336 is rated as high severity due to the presence of a hard-coded account that can be exploited by remote attackers.
2
How do I fix CVE-2017-7336?
To fix CVE-2017-7336, upgrade to Fortinet FortiWLM version 8.4.0 or higher where the hard-coded account vulnerability is resolved.
3
What software is affected by CVE-2017-7336?
CVE-2017-7336 affects Fortinet FortiWLM versions 8.3.0 and lower.
4
What kind of access does the hard-coded account provide in CVE-2017-7336?
The hard-coded account in CVE-2017-7336 allows attackers to log in and execute commands with 'upgrade' account privileges.
5
Can CVE-2017-7336 be exploited remotely?
Yes, CVE-2017-7336 can be exploited remotely due to the hard-coded account being accessible over the network.