Vulnerability Description
A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortiwlm | <= 8.3.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/99351Third Party AdvisoryVDB Entry
- https://fortiguard.com/advisory/FG-IR-17-115Vendor Advisory
- http://www.securityfocus.com/bid/99351Third Party AdvisoryVDB Entry
- https://fortiguard.com/advisory/FG-IR-17-115Vendor Advisory
FAQ
What is CVE-2017-7336?
CVE-2017-7336 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges.
How severe is CVE-2017-7336?
CVE-2017-7336 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-7336?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortiwlm.