CVE Vulnerabilities

CVE-2016-8494

Published: Feb 09, 2017 | Modified: Mar 01, 2017
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a new webui theme.

Affected Software

Name Vendor Start Version End Version
Connect Fortinet 14.2 (including) 14.2 (including)
Connect Fortinet 14.10 (including) 14.10 (including)
Connect Fortinet 15.10 (including) 15.10 (including)
Connect Fortinet 16.7 (including) 16.7 (including)

References