PostgreSQL User Credential Vulnerability in Fortinet FortiAuthenticator
CVE-2015-1455

Currently unrated

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
3 February 2015

Summary

Fortinet FortiAuthenticator version 3.0.0 contains a significant vulnerability where the default passwords for the 'slony' and 'www-data' PostgreSQL users are set to easily guessable values. This weak security practice allows remote attackers to exploit these credentials to gain unauthorized access, potentially compromising the system's operations and data integrity. Organizations using this version are advised to apply necessary patches and update user credentials to mitigate risks associated with remote exploitation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.