Fortinet FortiOS
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*
- >= 7.0.0, <= 7.0.16
This vulnerability is being actively exploited in the wild.
A vulnerability allowing authentication bypass via an alternate path or channel has been identified in Fortinet FortiOS versions 7.0.0 to 7.0.16, as well as FortiProxy versions 7.0.0 to 7.0.19 and 7.2.0 to 7.2.12. This vulnerability allows remote attackers to gain super-admin privileges by sending crafted requests to the Node.js WebSocket module.
Exploiting this vulnerability allows remote attackers to bypass authentication and gain super-admin privileges on the affected system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.