CVE-2019-13402: High severity fortinet fcm-mb40 firmware vulnerability
/usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incomplete factory-reset process. A backdoor can persist because neither system accounts nor the set of services is reset.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13402?
CVE-2019-13402 has a medium severity rating due to its potential for exploitation through a backdoor that persists after a factory reset.
How do I fix CVE-2019-13402?
To remediate CVE-2019-13402, consider upgrading the Fortinet FCM-MB40 firmware to a version that addresses this vulnerability.
What devices are affected by CVE-2019-13402?
CVE-2019-13402 affects Dynacolor FCM-MB40 devices running firmware version 1.2.0.0.
What does the CVE-2019-13402 vulnerability allow an attacker to do?
CVE-2019-13402 allows an attacker to exploit an incomplete factory-reset process, potentially allowing access to system accounts and services.
Is there a known workaround for CVE-2019-13402?
As of now, there is no official workaround for CVE-2019-13402, and upgrading firmware is the recommended action.