CVE-2019-16153: Critical severity fortinet fortisiem windows agent vulnerability
A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-16153?
CVE-2019-16153 is a hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below that may allow attackers to access the device database using static credentials.
How severe is CVE-2019-16153?
CVE-2019-16153 has a severity rating of 9.8 (Critical).
What software versions are affected by CVE-2019-16153?
CVE-2019-16153 affects Fortinet FortiSIEM database component version 5.2.5 and below.
How can an attacker exploit CVE-2019-16153?
An attacker can exploit CVE-2019-16153 by using the hard-coded static credentials to gain unauthorized access to the Fortinet FortiSIEM device database.
Is there a fix available for CVE-2019-16153?
Yes, Fortinet has released a fix for CVE-2019-16153. It is recommended to update to a version above 5.2.5 to mitigate the vulnerability.