CVE-2019-17659

CVSS 3.1 Score 3.7 of 10 (low)

Details

Published Mar 17, 2025
CWE ID 798

Summary

CVE-2019-17659 is a vulnerability affecting FortiSIEM version 5.2.6. An attacker can exploit this issue by obtaining the hard-coded cryptographic key, which is common to multiple installations or firmware images. This key can be used to gain unauthenticated SSH access to the supervisor as the restricted user "tunneluser." The attacker does not need to have valid credentials to exploit this vulnerability, making it a significant security risk. Successful exploitation could lead to unauthorized access and potential data breaches. FortiGuard recommends updating to a patched version of FortiSIEM to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share