CVE-2018-1352: Critical severity fortios vulnerability
Published Feb 8, 2019
·Updated
A format string vulnerability in Fortinet FortiOS 5.6.0 allows attacker to execute unauthorized code or commands via the SSH username variable.
Affected Software
1 affected component
Fortinet FortiOS=5.6.0
Event History
Feb 8, 2019
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-1352?
CVE-2018-1352 is rated as a medium severity vulnerability due to its potential to allow unauthorized code execution.
2
How do I fix CVE-2018-1352?
To fix CVE-2018-1352, update FortiOS to a version that is not vulnerable, specifically versions above 5.6.0.
3
What types of attacks can exploit CVE-2018-1352?
CVE-2018-1352 can be exploited to execute unauthorized commands through manipulated SSH username variables.
4
Which versions of FortiOS are affected by CVE-2018-1352?
FortiOS version 5.6.0 is specifically affected by CVE-2018-1352.
5
Is there a workaround for CVE-2018-1352 if I cannot update?
Until an update can be applied, mitigating factors include restricting SSH access and monitoring for unusual activity.