CVE-2019-17659
published 2025-03-17CVE-2019-17659: A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the…
PriorityP353high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.62%
45.7th percentile
A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as the restricted user "tunneluser" by leveraging knowledge of the private key from another installation or a firmware image.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortisiem | < 5.2.7 | 5.2.7 |
| fortinet | fortisiem | — | — |
| fortinet | fortisiem | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8f4x-4qgh-w73f: A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5
ghsa_unreviewed·2025-03-17
CVE-2019-17659 [LOW] CWE-798 GHSA-8f4x-4qgh-w73f: A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5
A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as the restricted user "tunneluser" by leveraging knowledge of the private key from another installation or a firmware image.
Fortinet
A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attack...
vendor_fortinet·2025-03-17·CVSS 3.7
CVE-2019-17659 [LOW] CWE-798 A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attack...
FG-IR-19-296: A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attack...
A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as the restricted user "tunneluser" by leveraging knowledge of the private key from another installation or a firmware image.
CVEs: CVE-2019-17659
CWEs: CWE-798
CVSS: 3.7 (low)
Affected products: FortiSIEM
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-17
Published