← Back to CVE List
Vulnerability Intelligence Report

CVE-2016-1909

Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for the Fortimanager_Access account, which allows remote attackers to obtain administrative access via an SSH session.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:71.27%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
fortinet fortios 5.0, 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.6, 5.0.7

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
71.268%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2016-01-15T00:00:00
Published2016-01-15T20:00:00
Patch Date2016-01-11
Last Updated2024-08-05T23:10:40

LINK COPIED TO CLIPBOARD