QID 379130
Date Published: 2023-12-20
QID 379130: Fortinet FortiAnalyzer and FortiManager - Hardcoded Credentials Vulnerability (FG-IR-23-177)
A use of hard-coded credentials [CWE-798] in FortiManager and FortiAnalyzer may allow an attacker to access Fortinet dummy testing data via the use of static credentials. Those credentials have been revoked.
Affected Products:
FortiManager 7.4.0
FortiManager 7.2.0 through 7.2.3
FortiManager 7.0.0 through 7.0.8
FortiAnalyzer 7.4.0
FortiAnalyzer 7.2.0 through 7.2.3
FortiAnalyzer 7.0.0 through 7.0.8
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager and FortiAnalyzer.
Successful exploitation of this vulnerability may allow an attacker to access Fortinet dummy testing data via the use of static credentials.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-23-177
- FG-IR-23-177 -
www.fortiguard.com/psirt/FG-IR-23-177
CVEs related to QID 379130
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-23-177 |
|