QID 378664
QID 378664: Fortinet FortiAnalyzer and FortiManager - Path Traversal Vulnerability (FG-IR-22-471)
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface may allow a remote and authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
Affected Products:
FortiManager version 7.2.0 through 7.2.1
FortiManager version 7.0.0 through 7.0.5
FortiManager version 6.4.0 through 6.4.11
FortiAnalyzer version 7.2.0 through 7.2.1
FortiAnalyzer version 7.0.0 through 7.0.5
FortiAnalyzer version 6.4.0 through 6.4.11
QID Detection Logic (Authenticated):
Detection checks for vulnerable versions of FortiManager and FortiAnalyzer.
Successful exploitation of this vulnerability may allow a remote and authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
Vendor has released fixes to address this vulnerability
For more details refer advisory FG-IR-22-471
- FG-IR-22-471 -
www.fortiguard.com/psirt/FG-IR-22-471
CVEs related to QID 378664
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-22-471 |
|