CVE-2016-4573
9.8
CRITICAL · CVSS 3.0 · EPSS 4.6% (pctl 91)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D-FPOE, FSW-448D, FSW-448D-POE, FSW-448D-FPOE, FSW-524D, FSW-524D-FPOE, FSW-548D, FSW-548D-FPOE, FSW-1024D, FSW-1048D, FSW-3032D, and FSW-R-112D-POE models, when in FortiLink managed mode and upgraded to 3.4.1, might allow remote attackers to bypass authentication and gain administrative access via an empty password for the rest_admin account.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.56% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-09-09 |
| Last modified | 2026-06-17 |
Affected (22)
| Vendor | Product |
|---|---|
| fortinet | fortiswitch |
| fortinet | fsw-1024d |
| fortinet | fsw-1048d |
| fortinet | fsw-108d-poe |
| fortinet | fsw-124d |
| fortinet | fsw-124d-poe |
| fortinet | fsw-224d-fpoe |
| fortinet | fsw-224d-poe |
| fortinet | fsw-248d-fpoe |
| fortinet | fsw-248d-poe |
| fortinet | fsw-3032d |
| fortinet | fsw-424d |
| fortinet | fsw-424d-fpoe |
| fortinet | fsw-424d-poe |
| fortinet | fsw-448d |
| fortinet | fsw-448d-fpoe |
| fortinet | fsw-448d-poe |
| fortinet | fsw-524d |
| fortinet | fsw-524d-fpoe |
| fortinet | fsw-548d |
| fortinet | fsw-548d-fpoe |
| fortinet | fsw-r-112d-poe |
References
- http://fortiguard.com/advisory/fortiswitch-rest-admin-account-exposed-under-specific-conditions
- http://www.securityfocus.com/bid/92450
- https://www.themissinglink.com.au/security/advisories/cve-2016-4573
- http://fortiguard.com/advisory/fortiswitch-rest-admin-account-exposed-under-specific-conditions
- http://www.securityfocus.com/bid/92450
- https://www.themissinglink.com.au/security/advisories/cve-2016-4573
→ the Explorer · watch your stack · NVD