In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an underlying SSH defect.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://fortiguard.com/advisory/FG-IR-14-010 | mitigation vendor advisory |