CVE-2019-6695
published 2019-08-23CVE-2019-6695: Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant…
PriorityP344critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.77%
51.3th percentile
Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant third-party programs by recreating the image through specific methods.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortimanager | <= 6.0.6 | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow...
vendor_fortinet·2019-06-04·CVSS 9.8
CVE-2019-5587 [MEDIUM] CWE-345 Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow...
FG-IR-19-017: Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow...
Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow attacker to implant malicious programs into the installing image by reassembling the image through specific methods.
Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant third-party programs by recreating the image through specific methods.
CVEs: CVE-2019-5587, CVE-2019-6695
CWEs: CWE-345
CVSS: 9.8 (critical)
Affected products: FortiManager, FortiOS, Fortinet
GHSA
GHSA-fqfh-95gw-rh8x: Lack of root file system integrity checking in Fortinet FortiManager VM application images of all versions below 6
ghsa_unreviewed·2022-05-24
CVE-2019-6695 [CRITICAL] CWE-345 GHSA-fqfh-95gw-rh8x: Lack of root file system integrity checking in Fortinet FortiManager VM application images of all versions below 6
Lack of root file system integrity checking in Fortinet FortiManager VM application images of all versions below 6.2.1 may allow an attacker to implant third-party programs by recreating the image through specific methods.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-08-23
Published