CVE-2016-8494

HIGH

Fortinet Connect - Authenticated Remote Code Execution via Theme Upload

Title source: llm
STIX 2.1

Description

Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a new webui theme.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-16-080
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96159

Scores

CVSS v3 7.2
EPSS 0.0107
EPSS Percentile 77.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-264
Status published
Products (8)
fortinet/connect 14.2
fortinet/connect 14.10
fortinet/connect 15.10
fortinet/connect 16.7
Fortinet/Fortinet Connect 14.10
Fortinet/Fortinet Connect 14.2
Fortinet/Fortinet Connect 15.10
Fortinet/Fortinet Connect 16.7
Published Feb 09, 2017
Tracked Since Feb 18, 2026