Vulnerability Details CVE-2016-8491
The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.3%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 9.4
Products affected by CVE-2016-8491
-
cpe:2.3:h:fortinet:fortiwlc:7.0-10-0
-
cpe:2.3:h:fortinet:fortiwlc:7.0-9-1
-
cpe:2.3:h:fortinet:fortiwlc:8.1-2-0
-
cpe:2.3:h:fortinet:fortiwlc:8.1-3-2
-
cpe:2.3:h:fortinet:fortiwlc:8.2-4-0