Use of Hard-Coded Credentials in FortiTester Products
CVE-2023-40717
5MEDIUM
What is CVE-2023-40717?
A vulnerability exists in FortiTester versions 2.3.0 through 7.2.3 due to the presence of hard-coded credentials. An attacker who gains shell access to the device could exploit this weakness to execute shell commands for unauthorized database access, potentially compromising sensitive data and system integrity.
Affected Version(s)
FortiTester 7.2.0 <= 7.2.3
FortiTester 7.1.0 <= 7.1.1
FortiTester 7.0.0