CVE-2016-4573

CRITICAL

Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D-FPOE, FSW-448D, FSW-448D-POE, FSW-448D-FPOE, FS...

Affects 22 products across 1 vendor.

BCS7.72
CVSS 3.09.8
EPSS4.6%
Percentile91th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-264: Permissions, Privileges, and Access Controls

Broad class covering failures in permission enforcement. Deprecated in favor of CWE-284, CWE-862, CWE-863.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2016. A critical vulnerability affects Fortinet systems (CVE-2016-4573). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2016-GLOBAL-254649-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2016-4573?
This vulnerability was disclosed in 2016. A critical vulnerability affects Fortinet systems (CVE-2016-4573). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2016-4573?
CVE-2016-4573 has CVSS 9.8 (Critical). Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 4.6%.
Is CVE-2016-4573 actively exploited?
No confirmed active exploitation of CVE-2016-4573 as of 2026-05-30.
How do I remediate CVE-2016-4573?
Priority: MEDIUM. Advisory: http://fortiguard.com/advisory/fortiswitch-rest-admin-account-exposed-under-specific-conditions PSIRT: [email protected]
What systems are affected by CVE-2016-4573?
CVE-2016-4573 affects: Fortinet, Fortinet, Fortinet, Fortinet, Fortinet, Fortinet, Fortinet, Fortinet.
Vulnerability Details
CVE IDCVE-2016-4573
BSIDBS-2016-GLOBAL-254649-C BreachSpider Global ID
CVSS VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2016-09-09
Last Modified2026-05-06
ICS Relevance75%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D-FPOE, FSW-448D, FSW-448D-POE, FSW-448D-FPOE, FSW-524D, FSW-524D-FPOE, FSW-548D, FSW-548D-FPOE, FSW-1024D, FSW-1048D, FSW-3032D, and FSW-R-112D-POE models, when in FortiLink managed mode and upgraded to 3.4.1, might allow remote attackers to bypass authentication and gain administrative access via an empty password for the rest_admin account.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D-FPOE, FSW-448D, FSW-448D-POE, FSW-448D-FPOE, FSW-524D, FSW-524D-FPOE, FSW-548D, FSW-548D-FPOE, FSW-1024D, FSW-1048D, FSW-3032D, and FSW-R-112D-POE models, when in FortiLink managed mode and upgraded to 3.4.1, might allow remote attackers to bypass authentication and gain administrative access via an empty password for the rest_admin account. CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Fortinet Fortiswitch
Fortinet Fsw-1024D
Fortinet Fsw-1048D
Fortinet Fsw-108D-Poe
Fortinet Fsw-124D
Fortinet Fsw-124D-Poe
Fortinet Fsw-224D-Fpoe
Fortinet Fsw-224D-Poe
Fortinet Fsw-248D-Fpoe
Fortinet Fsw-248D-Poe
Fortinet Fsw-3032D
Fortinet Fsw-424D
Fortinet Fsw-424D-Fpoe
Fortinet Fsw-424D-Poe
Fortinet Fsw-448D
Fortinet Fsw-448D-Fpoe
Fortinet Fsw-448D-Poe
Fortinet Fsw-524D
Fortinet Fsw-524D-Fpoe
Fortinet Fsw-548D
Fortinet Fsw-548D-Fpoe
Fortinet Fsw-R-112D-Poe
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 3606 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash3e6650938bdc51d12ee2e11337f6c6e052bd2360a283b9063808c0036f624d65a46b8918a2133e463a7b4d9783e197812b80cee37553b0650e413bf310dd7c67
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2024-47575 9.8 A missing authentication for critical function in FortiManager 7.6.0, FortiMa... CVE-2024-23109 9.8 An improper neutralization of special elements used in an os command ('os com... CVE-2024-23108 9.8 An improper neutralization of special elements used in an os command ('os com... CVE-2019-16153 9.8 A hard-coded password vulnerability in the Fortinet FortiSIEM database compon...
View all Fortinet CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →