Sploitus

CVE-2016-1909

8 known exploits for CVE-2016-1909

Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for the Fortimanager_Access account, which allows remote attackers to obtain administrative access via an SSH session.

Fortinet Fortios
≤ 4.3.16, 5.0, 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.6, 5.0.7
Fix
Available
CVSS 2.0
10.0 HIGH
CVSS 3.1
9.8 CRITICAL
EPSS
71.3% (99th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2016-01-15
CVE-2016-1909 at NVD
Authoritative description, scoring and affected products

8 known exploits for CVE-2016-1909

Proof-of-concept code and exploit modules indexed by Sploitus