First published: Tue Jun 04 2019(Updated: )
A path traversal vulnerability in the FortiProxy SSL VPN web portal may allow a non-authenticated, remote attacker to download FortiProxy system files through specially crafted HTTP resource requests.
Credit: psirt@fortinet.com psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS | >=5.6.3<=5.6.7 | |
Fortinet FortiOS | >=6.0.0<=6.0.4 | |
Fortinet FortiOS | ||
Fortinet FortiProxy | <1.2.9 | |
Fortinet FortiProxy | =2.0.0 | |
Fortinet FortiOS | >=5.4.6<5.4.13 | |
Fortinet FortiOS | >=5.6.3<5.6.8 | |
Fortinet FortiOS | >=6.0.0<6.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.