Vulnerability Description
Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a new webui theme.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Connect | 14.2 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/96159
- https://fortiguard.com/advisory/FG-IR-16-080Vendor Advisory
- http://www.securityfocus.com/bid/96159
- https://fortiguard.com/advisory/FG-IR-16-080Vendor Advisory
FAQ
What is CVE-2016-8494?
CVE-2016-8494 is a vulnerability with a CVSS score of 7.2 (HIGH). Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a new webui theme.
How severe is CVE-2016-8494?
CVE-2016-8494 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-8494?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Connect.