CVE-2019-17659: High severity fortinet fortisiem windows agent vulnerability
A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as the restricted user "tunneluser" by leveraging knowledge of the private key from another installation or a firmware image.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2019-17659?
CVE-2019-17659 has a critical severity rating due to the potential for remote unauthorized SSH access.
How do I fix CVE-2019-17659?
To mitigate CVE-2019-17659, update FortiSIEM to the latest version that addresses this vulnerability.
Who is affected by CVE-2019-17659?
Organizations using FortiSIEM version 5.2.6 are affected by CVE-2019-17659.
What type of attack can exploit CVE-2019-17659?
CVE-2019-17659 can be exploited by remote unauthenticated attackers gaining unauthorized SSH access.
What is the impact of CVE-2019-17659?
The impact of CVE-2019-17659 includes unauthorized access to sensitive systems and potential data breaches.