First published: Mon Jul 08 2019(Updated: )
/usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incomplete factory-reset process. A backdoor can persist because neither system accounts nor the set of services is reset.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet Fcm-mb40 Firmware | =1.2.0.0 | |
Fortinet Fcm-mb40 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13402 has a medium severity rating due to its potential for exploitation through a backdoor that persists after a factory reset.
To remediate CVE-2019-13402, consider upgrading the Fortinet FCM-MB40 firmware to a version that addresses this vulnerability.
CVE-2019-13402 affects Dynacolor FCM-MB40 devices running firmware version 1.2.0.0.
CVE-2019-13402 allows an attacker to exploit an incomplete factory-reset process, potentially allowing access to system accounts and services.
As of now, there is no official workaround for CVE-2019-13402, and upgrading firmware is the recommended action.