CVE-2015-7361Improper Authentication in Fortinet Fortios

Severity
9.3CRITICALNVD
EPSS
0.7%
top 27.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 15
Latest updateMay 17

Description

FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for access to the ZebOS shell on the HA dedicated management interface, which allows remote attackers to obtain shell access via unspecified vectors.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDfortinet/fortios5.2.3

🔴Vulnerability Details

2
GHSA
GHSA-rwq6-vx3r-72xr: FortiOS 52022-05-17
CVEList
CVE-2015-7361: FortiOS 52015-10-15
CVE-2015-7361 — Improper Authentication in Fortinet | cvebase