CVE-2016-4573
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D-FPOE, FSW-448D, FSW-448D-POE, FSW-448D-FPOE, FSW-524D, FSW-524D-FPOE, FSW-548D, FSW-548D-FPOE, FSW-1024D, FSW-1048D, FSW-3032D, and FSW-R-112D-POE models, when in FortiLink managed mode and upgraded to 3.4.1, might allow remote attackers to bypass authentication and gain administrative access via an empty password for the rest_admin account.
Modelos Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D-FPOE, FSW-448D, FSW-448D-POE, FSW-448D-FPOE, FSW-524D, FSW-524D-FPOE, FSW-548D, FSW-548D-FPOE, FSW-1024D, FSW-1048D, FSW-3032D y FSW-R-112D-POE, cuando se encuentran en un modo FortiLink administrado y actualizado a la versión 3.4.1, podrían permitir a atacantes remotos eludir autenticación y obtener acceso administrativo a través de una contraseña vacía para la cuenta rest_admin.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-05-10 CVE Reserved
- 2016-09-09 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/92450 | Vdb Entry | |
https://www.themissinglink.com.au/security/advisories/cve-2016-4573 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://fortiguard.com/advisory/fortiswitch-rest-admin-account-exposed-under-specific-conditions | 2016-11-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-1024d Search vendor "Fortinet" for product "Fsw-1024d" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-1048d Search vendor "Fortinet" for product "Fsw-1048d" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-108d-poe Search vendor "Fortinet" for product "Fsw-108d-poe" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-124d Search vendor "Fortinet" for product "Fsw-124d" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-124d-poe Search vendor "Fortinet" for product "Fsw-124d-poe" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-224d-fpoe Search vendor "Fortinet" for product "Fsw-224d-fpoe" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-224d-poe Search vendor "Fortinet" for product "Fsw-224d-poe" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-248d-fpoe Search vendor "Fortinet" for product "Fsw-248d-fpoe" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-248d-poe Search vendor "Fortinet" for product "Fsw-248d-poe" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-3032d Search vendor "Fortinet" for product "Fsw-3032d" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-424d Search vendor "Fortinet" for product "Fsw-424d" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-424d-fpoe Search vendor "Fortinet" for product "Fsw-424d-fpoe" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-424d-poe Search vendor "Fortinet" for product "Fsw-424d-poe" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-448d Search vendor "Fortinet" for product "Fsw-448d" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-448d-fpoe Search vendor "Fortinet" for product "Fsw-448d-fpoe" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-448d-poe Search vendor "Fortinet" for product "Fsw-448d-poe" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-524d Search vendor "Fortinet" for product "Fsw-524d" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-524d-fpoe Search vendor "Fortinet" for product "Fsw-524d-fpoe" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-548d Search vendor "Fortinet" for product "Fsw-548d" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-548d-fpoe Search vendor "Fortinet" for product "Fsw-548d-fpoe" | - | - |
Safe
|
Fortinet Search vendor "Fortinet" | Fortiswitch Search vendor "Fortinet" for product "Fortiswitch" | 3.4.1 Search vendor "Fortinet" for product "Fortiswitch" and version "3.4.1" | - |
Affected
| in | Fortinet Search vendor "Fortinet" | Fsw-r-112d-poe Search vendor "Fortinet" for product "Fsw-r-112d-poe" | - | - |
Safe
|