PT-2005-3888 · Fortinet+1 · Fortigate+1

Mathieu Dessus

·

Published

2005-12-31

·

Updated

2017-07-11

·

CVE-2005-3057

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiGate versions prior to 3.0 MR1
Description The issue allows remote attackers to bypass the Fortinet FTP anti-virus engine. This can be achieved by sending a STOR command and uploading a file before the FTP server response has been sent. An example of this exploit has been demonstrated using LFTP.
Recommendations For versions prior to 3.0 MR1, update to version 3.0 MR1 or later to resolve the issue. As a temporary workaround, consider restricting access to the FTP component until a patch is available. Avoid using the FTP component for uploading files until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3057

Affected Products

Fortigate
Lftp