Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Fortinet FortiAuthenticator 3.0.0 allows local users to bypass intended restrictions and gain privileges by creating /tmp/privexec/dbgcore_enable_shell_access and executing the "shell" command.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Fortinet FortiAuthenticator 安全漏洞
Vulnerability Description
Fortinet FortiAuthenticator是美国飞塔(Fortinet)公司的系列安全认证软件,它可与FortiToken(双因子认证令牌)结合,向通过RADIUS或LDAP认证的第三方设备提供安全的双因子验证。 Fortinet FortiAuthenticator 3.0.0之前版本中存在安全漏洞。本地攻击者可通过创建/tmp/privexec/dbgcore_enable_shell_access URI并执行shell命令利用该漏洞绕过既定的限制,获取权限。
CVSS Information
N/A
Vulnerability Type
N/A