QID 43909

Date Published: 2022-10-17

QID 43909: FortiOS Path Traversal Vulnerability (FG-IR-21-181)

A relative path traversal [CWE-23] vulnerability in FortiOS may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of the server via the GET request of the login page.

Affected Products:
FortiOS version7.0.1 and 7.0.0

QID Detection Logic (Authenticated):
Detection checks for vulnerable version of FortiOS.

Vulnerable FortiOS may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of the server via the GET request of the login page.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Vendor has released fixes to address this vulnerability
    For more details refer advisory FG-IR-21-181

    Vendor References

    CVEs related to QID 43909

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-21-181 URL Logo www.fortiguard.com/psirt/FG-IR-21-181