cbcvebase.
CVE-2016-7560
published 2016-10-05

CVE-2016-7560: The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which allows…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which allows remote attackers to read or write to arbitrary files via unspecified vectors.

Affected

7 ranges
VendorProductVersion rangeFixed in
fortinetfortiwlc<= 6.1-2-29
fortinetfortiwlc
fortinetfortiwlc
fortinetfortiwlc
fortinetfortiwlc
fortinetfortiwlc
sambasamba>= 0 < 2:4.1.6+dfsg-1ubuntu2.14.04.132:4.1.6+dfsg-1ubuntu2.14.04.13

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv5.1MEDIUM