Fortinet
Fortinet Fcm-mb40 Firmware: vulnerabilities and CVEs
Fortinet Fcm-mb40 Firmware has 5 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs5
Last 12 months0
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13402 | High (8.8) | 1.5% | — | Jul 8, 2019 | /usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incomplete factory-reset process. A backdoor can persist because neither system… |
| CVE-2019-13401 | High (8.8) | 0.64% | — | Jul 8, 2019 | Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/. |
| CVE-2019-13400 | Critical (9.8) | 1.6% | — | Jul 8, 2019 | Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retrieved via cgi-bin/getuserinfo.cgi?mode=info. |
| CVE-2019-13399 | Medium (5.9) | 1.1% | — | Jul 8, 2019 | Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation. |
| CVE-2019-13398 | High (7.2) | 4.1% | — | Jul 8, 2019 | Dynacolor FCM-MB40 v1.2.0.0 devices allow remote attackers to execute arbitrary commands via a crafted parameter to a CGI script, as demonstrated by sed injection in cgi-bin/camctrl_save_profile.cgi (save parameter) and… |