PT-2021-6904 · Fortinet · Fortios+1
Published
2021-12-07
·
Updated
2021-12-09
·
CVE-2021-41024
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FortiOS versions 7.0.0 through 7.0.1
FortiProxy version 7.0.0
Description
A relative path traversal issue may allow an unauthenticated attacker to inject path traversal character sequences, potentially disclosing sensitive server information via a GET request to the login page. This could enable a remote attacker to gain unauthorized access to protected information and potentially elevate their privileges using a specially crafted GET request.
Recommendations
For FortiOS versions 7.0.0 through 7.0.1, consider restricting access to the login page until a patch is available.
For FortiProxy version 7.0.0, avoid using the GET request on the login page until the issue is resolved.
As a temporary workaround, consider disabling the login page functionality until a fix is provided.
Fix
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fortios
Fortiproxy