CVE-2016-8491

Severity
9.1CRITICAL
EPSS
0.3%
top 49.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 1
Latest updateMay 17

Description

The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

NVDfortinet/fortiwlc5 versions+4
CVEListV5fortinet/fortinet_fortiwlc5 versions+4

🔴Vulnerability Details

2
GHSA
GHSA-pxp7-p7xv-7463: The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell2022-05-17
CVEList
CVE-2016-8491: The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell2017-02-01

📋Vendor Advisories

1
Fortinet
The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write a...2017-02-01
CVE-2016-8491 (CRITICAL CVSS 9.1) | The presence of a hardcoded account | cvebase.io