CVE-2005-3057: Critical severity Fortinet FortiOS vulnerability
Published Dec 31, 2005
·Updated
The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by sending a STOR command and uploading a file before the FTP server response has been sent, as demonstrated using LFTP.
Affected Software
3 affected components
Fortinet FortiOS<=2.8_mr10
Fortinet FortiOS<=3_beta
Fortinet FortiGate=2.8
Event History
Dec 31, 2005
CVE Published
05:00 AM
Feb 15, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3057?
CVE-2005-3057 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2005-3057?
To mitigate CVE-2005-3057, upgrade FortiOS to version 3.0 MR1 or later.
3
What components are affected by CVE-2005-3057?
The vulnerability affects the FTP component in FortiGate 2.8 and FortiOS versions before 3.0 MR1.
4
Can CVE-2005-3057 be exploited remotely?
Yes, CVE-2005-3057 can be exploited remotely by attackers sending a STOR command.
5
What does the CVE-2005-3057 vulnerability allow attackers to do?
CVE-2005-3057 allows attackers to bypass the FTP anti-virus engine by uploading files before the server response.