Overview
The Fortinet FortiWAN (Ascernlink) network load balancer appliance contains multiple vulnerabilities.
Description
According to the reporter, the Fortinet FortiWAN network load balancer appliance contains the following vulnerabilities. CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') - CVE-2016-4965 |
Impact
An authenticated but low-privileged (non-administrator) account may be able to execute OS commands in the root context, capture network traffic through the FortiWAN device, obtain appliance system configuration, or conduct cross-site scripting attacks against administrator users. |
Solution
Apply an update |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| Temporal | 8 | E:POC/RL:U/RC:UR |
| Environmental | 6.0 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Virgoteam (Fan-Syun Shih, Kun-Xian Lin, and Yu-Chi Ding) for reporting these vulnerabilities.
This document was written by Garret Wassermann.
Other Information
| CVE IDs: | CVE-2016-4965, CVE-2016-4966, CVE-2016-4967, CVE-2016-4968, CVE-2016-4969 |
| Date Public: | 2016-09-06 |
| Date First Published: | 2016-09-06 |
| Date Last Updated: | 2016-09-09 17:12 UTC |
| Document Revision: | 28 |