CVE-2016-7541
Last modified
CVE-2016-7541 is a vulnerability of currently unknown severity. Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during IPS signature updates when the FortiGate's IPSengine is configured in flow mode. All FortiGate versions with IPS configured in proxy mode (the default mode) are not affected.. EPSS estimates a 0.95% chance of exploitation in the next 30 days.
Description
Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during IPS signature updates when the FortiGate's IPSengine is configured in flow mode. All FortiGate versions with IPS configured in proxy mode (the default mode) are not affected.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortios | 5.0.0 |
| Fortinet | Fortios | 5.0.1 |
| Fortinet | Fortios | 5.0.2 |
| Fortinet | Fortios | 5.0.3 |
| Fortinet | Fortios | 5.0.4 |
| Fortinet | Fortios | 5.0.5 |
| Fortinet | Fortios | 5.0.6 |
| Fortinet | Fortios | 5.0.7 |
| Fortinet | Fortios | 5.0.8 |
| Fortinet | Fortios | 5.0.9 |
| Fortinet | Fortios | 5.0.10 |
| Fortinet | Fortios | 5.0.11 |
| Fortinet | Fortios | 5.0.12 |
| Fortinet | Fortios | 5.0.13 |
| Fortinet | Fortios | 5.0.14 |
| Fortinet | Fortios | 5.2.0 |
| Fortinet | Fortios | 5.2.1 |
| Fortinet | Fortios | 5.2.2 |
| Fortinet | Fortios | 5.2.3 |
| Fortinet | Fortios | 5.2.4 |
| Fortinet | Fortios | 5.2.5 |
| Fortinet | Fortios | 5.2.6 |
| Fortinet | Fortios | 5.2.7 |
| Fortinet | Fortios | 5.2.8 |
| Fortinet | Fortios | 5.2.9 |
| Fortinet | Fortios | 5.2.10 |
References
- http://fortiguard.com/advisory/FG-IR-16-088Not Applicable
- http://www.securityfocus.com/bid/94477Third Party Advisory, VDB Entry
- http://fortiguard.com/advisory/FG-IR-16-088Not Applicable
- http://www.securityfocus.com/bid/94477Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-7541?
How severe is CVE-2016-7541?
How do I fix CVE-2016-7541?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-7535coders/psd.c in ImageMagick allows remote attackers to cause…6.5
- CVE-2016-7536magick/profile.c in ImageMagick allows remote attackers to c…6.5
- CVE-2016-7537MagickCore/memory.c in ImageMagick allows remote attackers t…6.5
- CVE-2016-7538coders/psd.c in ImageMagick allows remote attackers to cause…6.5
- CVE-2016-7539Memory leak in AcquireVirtualMemory in ImageMagick before 7 …
- CVE-2016-7540coders/rgf.c in ImageMagick before 6.9.4-10 allows remote at…
- CVE-2016-7542A read-only administrator on Fortinet devices with FortiOS 5…
- CVE-2016-7543Bash before 4.4 allows local users to execute arbitrary comm…
- CVE-2016-7544Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _mal…
- CVE-2016-7545SELinux policycoreutils allows local users to execute arbitr…
- CVE-2016-7547A command execution flaw on the Trend Micro Threat Discovery…
- CVE-2016-7549Google Chrome before 53.0.2785.113 does not ensure that the …
Are you affected by CVE-2016-7541?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
