FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
fropert_FTNT
Staff
Staff
Article Id 190289
Description
Some vulnerability scanners incorrectly report FortiAnalyzer and FortiManager as vulnerable to CVE-2014-2532.

The security issue mentions that OpenSSH does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.

In reality, FortiAnalyzer and FortiManager are not affected by CVE-2014-2532 vulnerability.  These products are configured to ignore any environment variables configured with the -o SendEnv option sent from the SSH client.

Contributors