CRITICAL · 9.8

CVE-2016-4573

Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D-FPOE, FSW-448D, FSW-448D-POE, FSW-448D-FPOE, FSW-5...

Vulnerability Description

Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D-FPOE, FSW-448D, FSW-448D-POE, FSW-448D-FPOE, FSW-524D, FSW-524D-FPOE, FSW-548D, FSW-548D-FPOE, FSW-1024D, FSW-1048D, FSW-3032D, and FSW-R-112D-POE models, when in FortiLink managed mode and upgraded to 3.4.1, might allow remote attackers to bypass authentication and gain administrative access via an empty password for the rest_admin account.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
FortinetFortiswitch3.4.1
FortinetFsw-1024D-
FortinetFsw-1048D-
FortinetFsw-108D-Poe-
FortinetFsw-124D-
FortinetFsw-124D-Poe-
FortinetFsw-224D-Fpoe-
FortinetFsw-224D-Poe-
FortinetFsw-248D-Fpoe-
FortinetFsw-248D-Poe-
FortinetFsw-3032D-
FortinetFsw-424D-
FortinetFsw-424D-Fpoe-
FortinetFsw-424D-Poe-
FortinetFsw-448D-
FortinetFsw-448D-Fpoe-
FortinetFsw-448D-Poe-
FortinetFsw-524D-
FortinetFsw-524D-Fpoe-
FortinetFsw-548D-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-4573?

CVE-2016-4573 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D-FPOE, FSW-448D, FSW-448D-POE, FSW-448D-FPOE, FSW-5...

How severe is CVE-2016-4573?

CVE-2016-4573 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2016-4573?

Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortiswitch, Fortinet Fsw-1024D, Fortinet Fsw-1048D, Fortinet Fsw-108D-Poe, Fortinet Fsw-124D.