#VU24132 Use of Hard-coded Cryptographic Key in FortiSIEM - CVE-2019-17659
Published: January 8, 2020 / Updated: January 16, 2020
FortiSIEM
Fortinet, Inc
Description
The vulnerability allows a remote attacker to gain unauthorized access to the system.
The vulnerability exists due to usage of a hard-coded ssh key for the "tunneluser" account, present in "/home/tunneluser/.ssh/authorized_keys". A remote attacker can use the ssh key to connect to FortiSIEM via SSH service on port 1999/TCP.