FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for access to the ZebOS shell on the HA dedicated management interface, which allows remote attackers to obtain shell access via unspecified vectors.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2015-10-15T20:00:00

Updated: 2016-11-30T18:57:01

Reserved: 2015-09-25T00:00:00


Link: CVE-2015-7361

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2015-10-15T20:59:01.833

Modified: 2016-12-03T03:12:51.817


Link: CVE-2015-7361

JSON object: View

cve-icon Redhat Information

No data.

CWE