First published: Fri Feb 08 2019(Updated: )
A format string vulnerability in Fortinet FortiOS 5.6.0 allows attacker to execute unauthorized code or commands via the SSH username variable.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
FortiOS | =5.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1352 is rated as a medium severity vulnerability due to its potential to allow unauthorized code execution.
To fix CVE-2018-1352, update FortiOS to a version that is not vulnerable, specifically versions above 5.6.0.
CVE-2018-1352 can be exploited to execute unauthorized commands through manipulated SSH username variables.
FortiOS version 5.6.0 is specifically affected by CVE-2018-1352.
Until an update can be applied, mitigating factors include restricting SSH access and monitoring for unusual activity.