vendor:
FortiOS
by:
Ricardo Longatto
7.5
CVSS
HIGH
Magic backdoor
287
CWE
Product Name: FortiOS
Affected Version From: 6.0.0
Affected Version To: 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10
Patch Exists: YES
Related CWE: CVE-2018-13382
CPE: a:fortinet:fortios
Other Scripts:
N/A
Platforms Tested: 6.0.4
2020
Fortinet FortiOS 6.0.4 – Unauthenticated SSL VPN User Password Modification
This exploit allow change users password from SSLVPN web portal by exploiting the Magic backdoor vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10.
Mitigation:
Upgrade to FortiOS 6.0.5 or later, 5.6.9 or later, or 5.4.11 or later.