CVE-2019-13400: Critical severity fortinet fcm-mb40 firmware vulnerability
Published Jul 8, 2019
·Updated
Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retrieved via cgi-bin/getuserinfo.cgi?mode=info.
Affected Software
2 affected components
Fortinet Fcm-mb40 Firmware=1.2.0.0
Fortinet Fcm-mb40
Event History
Jul 8, 2019
CVE Published
via MITRE·12:02 AM
Data Sourced
via MITRE·12:02 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13400?
CVE-2019-13400 is rated as a high severity vulnerability due to the exposure of administrative credentials.
2
How do I fix CVE-2019-13400?
To fix CVE-2019-13400, ensure that administrative credentials are stored securely and not in cleartext.
3
What are the potential impacts of CVE-2019-13400?
The potential impacts of CVE-2019-13400 include unauthorized access to the administrative interface and possible system compromise.
4
Who is affected by CVE-2019-13400?
CVE-2019-13400 affects users of the Dynacolor FCM-MB40 firmware version 1.2.0.0.
5
What type of vulnerability is CVE-2019-13400?
CVE-2019-13400 is a credentials management vulnerability due to cleartext storage of sensitive information.