Fortinet Fcm-Mb40 Firmware vulnerabilities
5 known vulnerabilities affecting fortinet/fcm-mb40_firmware.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2019-13400CRITICALCVSS 9.8v1.2.0.02019-07-08
CVE-2019-13400 [CRITICAL] CWE-522 CVE-2019-13400: Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface creden
Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retrieved via cgi-bin/getuserinfo.cgi?mode=info.
nvd
CVE-2019-13402HIGHCVSS 8.8v1.2.0.02019-07-08
CVE-2019-13402 [HIGH] CWE-212 CVE-2019-13402: /usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB
/usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incomplete factory-reset process. A backdoor can persist because neither system accounts nor the set of services is reset.
nvd
CVE-2019-13398HIGHCVSS 7.2v1.2.0.02019-07-08
CVE-2019-13398 [HIGH] CWE-78 CVE-2019-13398: Dynacolor FCM-MB40 v1.2.0.0 devices allow remote attackers to execute arbitrary commands via a craft
Dynacolor FCM-MB40 v1.2.0.0 devices allow remote attackers to execute arbitrary commands via a crafted parameter to a CGI script, as demonstrated by sed injection in cgi-bin/camctrl_save_profile.cgi (save parameter) and cgi-bin/ddns.cgi.
nvd
CVE-2019-13401HIGHCVSS 8.8v1.2.0.02019-07-08
CVE-2019-13401 [HIGH] CWE-352 CVE-2019-13401: Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/.
Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/.
nvd
CVE-2019-13399MEDIUMCVSS 5.9v1.2.0.02019-07-08
CVE-2019-13399 [MEDIUM] CWE-798 CVE-2019-13399: Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrat
Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation.
nvd