First published: Sat Jul 22 2017(Updated: )
A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiWLM MEA for FortiManager | <=8.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7336 is rated as high severity due to the presence of a hard-coded account that can be exploited by remote attackers.
To fix CVE-2017-7336, upgrade to Fortinet FortiWLM version 8.4.0 or higher where the hard-coded account vulnerability is resolved.
CVE-2017-7336 affects Fortinet FortiWLM versions 8.3.0 and lower.
The hard-coded account in CVE-2017-7336 allows attackers to log in and execute commands with 'upgrade' account privileges.
Yes, CVE-2017-7336 can be exploited remotely due to the hard-coded account being accessible over the network.