<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>FortiBalancer Remote SSH Vulnerability</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-14-010</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2014-04-02T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2014-04-02T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2014-04-02T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Description" Type="General" Ordinal="1">
            A platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an underlying SSH defect.
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="2">
            Remote Access
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="3">
            FortiBalancer 400, 1000, 2000 and 3000.All software versions are affected.
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="4">
            Apply the patch provided on the Fortinet Support site, or use one of the workarounds shown below. The patch and supporting documentation are available in the FortiBalancer firmware download directory, accessible from https://support.fortinet.com. The following files are available:FortiBalancer-Component-Patch.pdf - Installation InstructionsFBLOS-FortiBalancer-Patch-2014_02.fn - System patchOther Workarounds:1. Disable SSH on the Web UI via Admin Tools -&gt; System Management. Uncheck &#34;enable SSH access&#34; and click &#34;save changes&#34; on the top right.2. Disable SSH in the console via:config tssh offwrite memoryexit3. Use Webwall rules in order to block TCP port 22 destined to the load balancer external IP address:config taccesslist deny tcp 0.0.0.0 0.0.0.0 0 &lt;external-ip-address&gt; 255.255.255.255 22 100accesslist permit tcp 0.0.0.0 0.0.0.0 0 0.0.0.0 0.0.0.0 0 100accessgroup 100 &lt;external-port&gt;webwall &lt;external-port&gt; onwrite memoryexit4. Use a firewall to block TCP port 22 access to the FortiBalancer.
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <Vulnerability Ordinal="1">
        <Title>FortiBalancer Remote SSH Vulnerability</Title>
        <cvrf:CVE>CVE-2014-2721 password issue</cvrf:CVE>
        <cvrf:CVE>CVE-&lt;br /&gt;2014-2722 key issue</cvrf:CVE>
        <cvrf:CVE>CVE-&lt;br /&gt;2014-2723 permission issue</cvrf:CVE>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-14-010</URL>
                <Description>FortiBalancer Remote SSH Vulnerability</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>