vendor:
FortiGate OS
by:
Anonymous
8,8
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: FortiGate OS
Affected Version From: 4.x
Affected Version To: 5.0.7
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2020
SSH Backdoor for FortiGate OS Version 4.x up to 5.0.7
This exploit allows an attacker to bypass authentication on FortiGate OS Version 4.x up to 5.0.7 by using a custom handler to generate a valid authentication token. The exploit uses a hardcoded key to generate the token, which is then used to authenticate the user.
Mitigation:
Upgrade to FortiGate OS Version 5.0.8 or later.