First published: Thu Dec 19 2024(Updated: )
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. In particular, deleting specific configuration files will reset the Admin password to its default value.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiWan | <=4.5.7=4.4 | |
Fortinet FortiWan | >=4.4.0<4.5.8 |
Please upgrade to FortiWAN version 4.5.8 or above Please upgrade to AscenLink version 7.2.24 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.