Fortinet FortiSIEM Hard-Coded Cryptographic Key Vulnerability Allowing Unauthorized SSH Access

Vulnerability

A vulnerability exists in Fortinet FortiSIEM version 5.2.6 due to the use of a hard-coded cryptographic key. This vulnerability may enable a remote, unauthenticated attacker to gain SSH access to the supervisor as the restricted user 'tunneluser'. Exploitation requires knowledge of the private key from another installation or a firmware image.

Impact

Exploitation of this vulnerability could lead to unauthorized SSH access on the affected system, allowing for potential further exploitation or manipulation of the system under the 'tunneluser' account.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
1.3
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.